CVE-2019-7576
07.02.2019, 07:29
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).Enginsight
| Vendor | Product | Version |
|---|---|---|
| libsdl | simple_directmedia_layer | 𝑥 ≤ 1.2.15 |
| libsdl | simple_directmedia_layer | 2.0.0 ≤ 𝑥 ≤ 2.0.9 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 15.0 |
| opensuse | leap | 42.3 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libsdl1.2 |
| ||||||||||||||||||||||||||||||
| libsdl2 |
|
Common Weakness Enumeration
References