SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 9.0 | 9.0.x |
fedoraproject / fedora | 33 | 33.x |
libsdl / simple_directmedia_layer | 2.0.12 | 2.0.20.x |