SB2018031106 - Stack-based buffer overflow in sdl2_image (Alpine package)
Published: March 11, 2018
Security Bulletin ID
SB2018031106
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2017-14440)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The weakness exists in the ILBM image rendering functionality due to stack-based buffer overflow. A remote attacker can send a specially crafted image, trick the victim into opening it and execute arbitrary code.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1fe32d61beb6c5514a0fb76fc98cf6feab7aae65
- https://git.alpinelinux.org/aports/commit/?id=9f6b061f48c397e4e666fcf6f75fabe92b6033d2
- https://git.alpinelinux.org/aports/commit/?id=9f0236c2477637c822aa9ce33b3648f74607c3da
- https://git.alpinelinux.org/aports/commit/?id=2271c9b08f83a5ddae09fe4007b3ead3a9e03c26
- https://git.alpinelinux.org/aports/commit/?id=53eca00d555f64bd2da618c0ae5cdfbee8670f4a