UBUNTU-CVE-2017-2888
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-2888
UBUNTU-CVE-2017-2888
Summary:
Details: An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2017-2888, https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0395, https://ubuntu.com/security/notices/USN-4143-1, https://www.cve.org/CVERecord?id=CVE-2017-2888
Affected packages
Package
Name: libsdl2
Purl: pkg:deb/ubuntu/[email protected]+dfsg1-2ubuntu2.16.04.2?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
