漏洞信息详情

Simple DirectMedia Layer 缓冲区错误漏洞

  • CNNVD编号:CNNVD-201902-178
  • 危害等级: 高危
  • CVE编号: CVE-2019-7638
  • 漏洞类型: 缓冲区错误
  • 发布时间: 2019-02-08
  • 威胁类型: 远程
  • 更新时间: 2020-11-05
  • 厂        商:
  • 漏洞来源: Ubuntu,Red Hat,Gen...

漏洞简介

Simple DirectMedia Layer(SDL)是一个用于用于访问低级硬件和图形,并为游戏、软件和仿真器提供支持的多平台库。

SDL 1.2.15及之前版本和2.x版本至2.0.9版本中的video/SDL_pixels.c文件的‘Map1toN’函数存在缓冲区错误漏洞。攻击者可借助特制的文件利用该漏洞在系统上执行任意代码。

漏洞公告

目前厂商暂未发布修复措施解决此安全问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决办法:

https://www.libsdl.org/

参考网址

来源:ESB-2019.0827~ESB-2019.0825

链接:无

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00063.html

来源:GENTOO

链接:https://security.gentoo.org/glsa/201909-07

来源:MISC

链接:https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720

来源:discourse.libsdl.org

链接:https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720Vendor Advisory

来源:bugzilla.libsdl.org

链接:https://bugzilla.libsdl.org/show_bug.cgi?id=4500ExploitIssue TrackingVendor Advisory

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/03/msg00016.html

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00073.html

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00088.html

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/03/msg00015.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-201913998-1.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190917-1.html

来源:usn.ubuntu.com

链接:https://usn.ubuntu.com/4156-1/

来源:lists.debian.org

链接:https://lists.debian.org/debian-lts-announce/2019/03/msg00016.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190899-1.html

来源:www.suse.com

链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190950-1.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/78706

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/78158

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/78610

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/79106

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159341/Red-Hat-Security-Advisory-2020-3868-01.html

来源:nvd.nist.gov

链接:https://nvd.nist.gov/vuln/detail/CVE-2019-7638

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/77126

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/154394/Gentoo-Linux-Security-Advisory-201909-07.html

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/159883/Red-Hat-Security-Advisory-2020-4627-01.html

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3383/

来源:vigilance.fr

链接:https://vigilance.fr/vulnerability/SDL-multiple-vulnerabilities-28595

受影响实体

    暂无


补丁

    暂无

漏洞信息快速查询

相关漏洞

更多