Description
An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1134-1 | sdl-image1.2 security update |
Debian DSA |
DSA-4177-1 | libsdl2-image security update |
Debian DSA |
DSA-4184-1 | sdl-image1.2 security update |
EUVD |
EUVD-2017-12028 | An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability. |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-09-17T02:57:14.504Z
Reserved: 2016-12-01T00:00:00.000Z
Link: CVE-2017-2887
No data.
Status : Modified
Published: 2017-10-11T18:29:04.943
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-2887
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD