CVE-2019-5058 PUBLISHED

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

EPSS 0.99% · 76.7th percentile

Risk Scores

EPSS Score
0.99%
76.7th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlibsdl2-image0
Ubuntu:Pro:14.04:LTSlibsdl2-image2.0.0+dfsg-2, 2.0.0+dfsg-3, 2.0.0+dfsg-3build2
Ubuntu:16.04:LTSlibsdl2-image2.0.0+dfsg-3build2, 2.0.1+dfsg-1, 2.0.1+dfsg-2
Ubuntu:18.04:LTSlibsdl2-image2.0.1+dfsg-3, 2.0.1+dfsg-4, 2.0.2+dfsg1-1

Timeline

References

Open in Interactive Console →