CVE-2020-14410 PUBLISHED

SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.

EPSS 0.16% · 36.9th percentile

Risk Scores

EPSS Score
0.16%
36.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSlibsdl22.0.6+dfsg1-3ubuntu1, 2.0.7+dfsg1-3ubuntu1, 2.0.8+dfsg1-1ubuntu1
Ubuntu:Pro:20.04:LTSlibsdl22.0.10+dfsg1-1ubuntu1, 2.0.10+dfsg1-1ubuntu4, 2.0.10+dfsg1-1ubuntu7

Timeline

References

Open in Interactive Console →