CVE-2020-14409 PUBLISHED

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

EPSS 0.20% · 42.0th percentile

Risk Scores

EPSS Score
0.20%
42.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSlibsdl20, 2.0.6+dfsg1-3ubuntu1, 2.0.6+dfsg1-4ubuntu1
Ubuntu:Pro:20.04:LTSlibsdl20, 2.0.10+dfsg1-1ubuntu1, 2.0.10+dfsg1-1ubuntu4

Timeline

References

Open in Interactive Console →