An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| libsdl / sdl_image | 2.0.2 | 2.0.2.x |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| starwindsoftware / starwind_virtual_san | 8-build12533 | 8-build12533.x |
| starwindsoftware / starwind_virtual_san | 8-build12658 | 8-build12658.x |
| starwindsoftware / starwind_virtual_san | 8-build12859 | 8-build12859.x |