Skip to main content

Detection of Error Condition Without Action

CVE-2019-5051

Severity High
Score 8.8/10

Summary

An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • HIGH

CWE-390 - Detection of Error Condition Without Action

The software detects a specific error, but takes no actions to handle the error.

References

Advisory Timeline

  • Published