SB2018031104 - Buffer overflow in sdl2_image (Alpine package)
Published: March 11, 2018
Security Bulletin ID
SB2018031104
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2017-14450)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists in the GIF image parsing functionality due to buffer overflow. A remote attacker can send a specially crafted image, trick the victim into opening it and execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=a798fa69a2e2d9f2cc876d181cd7d5a9a106b1b9
- https://git.alpinelinux.org/aports/commit/?id=9f0236c2477637c822aa9ce33b3648f74607c3da
- https://git.alpinelinux.org/aports/commit/?id=2271c9b08f83a5ddae09fe4007b3ead3a9e03c26
- https://git.alpinelinux.org/aports/commit/?id=53eca00d555f64bd2da618c0ae5cdfbee8670f4a