Vulnerability nyob rau hauv lub tsev qiv ntawv SDL ua rau kev ua txhaum cai thaum ua cov duab

Nyob rau hauv ib txheej ntawm cov tsev qiv ntawv SDL (Yooj yim Direct Layer), uas muab cov cuab yeej rau kev kho vajtse nrawm 2D thiab 3D cov duab tso tawm, kev tawm tswv yim, kev rov ua suab, 3D tso tawm ntawm OpenGL / OpenGL ES thiab ntau lwm yam haujlwm, qhia tawm 6 vulnerabilities. Tshwj xeeb, ob qhov teeb meem tau pom nyob rau hauv lub tsev qiv ntawv SDL2_image uas ua rau nws muaj peev xwm los teeb tsa tej thaj chaw deb kev ua tiav hauv lub kaw lus. Kev tawm tsam tuaj yeem ua tiav ntawm cov ntawv thov uas siv SDL los thauj cov duab.

Ob qhov tsis zoo (CVE-2019-5051, SWB-2019-5051) yog tam sim no nyob rau hauv IMG_LoadPCX_RW muaj nuj nqi thiab yog tshwm sim los ntawm tsis muaj ib tug tsim nyog yuam kev handler thiab integer overflow, uas yuav raug exploited los ntawm dhau ib tug tshwj xeeb formatted PCX ntaub ntawv. Cov teeb meem twb muaj lawm tshem tawm hauv qhov teeb meem SDL_image 2.0.5. Cov ntaub ntawv hais txog qhov seem 4 qhov tsis zoo txog tam sim no tsis qhia tawm.

Tau qhov twg los: opennet.ru

Ntxiv ib saib