CVE-2021-33657
Summary
| CVE | CVE-2021-33657 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-01 23:15:00 UTC |
| Updated | 2023-05-03 12:15:00 UTC |
| Description | There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| libsdl: Multiple Vulnerabilities (GLSA 202305-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 3314-1] libsdl2 security update |
MLIST |
lists.debian.org |
|
| Always create a full 256-entry map in case color values are out of range · libsdl-org/SDL@8c91cf7 · GitHub |
MISC |
github.com |
|
| libsdl2: Multiple Vulnerabilities (GLSA 202305-18) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180830 Debian Security Update for libsdl2 (CVE-2021-33657)
- 181548 Debian Security Update for libsdl2 (DLA 3314-1)
- 198762 Ubuntu Security Notification for Simple DirectMedia Layer Vulnerability (USN-5398-1)
- 296100 Oracle Solaris 11.4 Support Repository Update (SRU) 58.144.3 Missing (CPUAPR2023)
- 502366 Alpine Linux Security Update for sdl2
- 710710 Gentoo Linux libsdl Multiple Vulnerabilities (GLSA 202305-17)
- 710723 Gentoo Linux libsdl2 Multiple Vulnerabilities (GLSA 202305-18)
- 752041 SUSE Enterprise Linux Security Update for SDL2 (SUSE-SU-2022:1218-1)
- 752055 SUSE Enterprise Linux Security Update for SDL (SUSE-SU-2022:1273-1)
- 752070 SUSE Enterprise Linux Security Update for SDL (SUSE-SU-2022:1312-1)
- 752072 SUSE Enterprise Linux Security Update for SDL2 (SUSE-SU-2022:1313-1)
- 753165 SUSE Enterprise Linux Security Update for SDL (SUSE-SU-2022:14943-1)