suse · CVE-2018-3977

Quick triage

Priority: high Published: 2021-05-30 14:08:21 UTC Updated: 2023-12-09 00:55:09 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-3977 severity important: SUSE including 15 source package names (SDL_image-1.2.6-84.46.1, SDL_image-devel-1.2.6-84.46.1, …), 15 product×package rows across 5 product lines (SUSE Linux Enterprise Software Development Kit 11 SP4, SUSE Package Hub 15, … (5 product lines)): Fixed 15.

Description:

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

cvelogic Threat Intelligence