[/caption]
multiplication video games
Researchers at Cisco’s Talos aegis intelligence and analysis accumulation accept apparent two aerial severity alien cipher beheading vulnerabilities in Simple DirectMedia Layer (SDL), a accepted cross-platform development library.
[caption id="" align="aligncenter" width="400px"][/caption]
SDL provides low akin admission to audio, mouse, keyboard, joystick and cartoon hardware, authoritative it ideal for developing games, emulators and video playback software. The library has been acclimated for the development of hundreds of games, including ones fabricated by Valve, and the VLC media player.
Cisco Talos researcher Yves Younan apparent that SDL is afflicted by anamnesis bribery vulnerabilities that can be exploited accidentally to assassinate approximate cipher on the host by application distinctively crafted files that the library would process.
The advance scenarios declared by Talos in its advisories absorb XCF files advised to activate the vulnerabilities. XCF is the built-in angel architecture of the accepted image-editing apparatus GIMP.
[caption id="" align="aligncenter" width="400px"][/caption]
One of the flaws is an accumulation overflow (CVE-2017-2888) that can be triggered back creating a new RGB apparent via a alarm to the “CreateRGBSurface” function.
“A abundantly ample amplitude and acme amount anesthetized to this action could account a multiplication operation to overflow, appropriately consistent in too little anamnesis actuality allocated. Consecutive writes would again be out-of-bounds,” Cisco said in its advisory.
The additional vulnerability is a absorber overflow (CVE-2017-2887) that exists in the XCF acreage administration functionality of the SDL_image angel book loading library.
[caption id="" align="aligncenter" width="400px"][/caption]
“This vulnerability manifests due to bereft validation of abstracts apprehend from a book and consecutive use of the data. In this case, the `id` and `length` attributes apprehend from an XCF angel book are acclimated after validation, potentially consistent in a stack-based absorber overflow,” Cisco said.
The vulnerabilities affect SDL 2.0.5 and SDL_image 2.0.1. Cisco said the flaws were patched with the absolution of SDL 2.0.6, but the absolution addendum for this adaptation don’t acknowledgment any aegis fixes.
Related: Cipher Beheading Vulnerabilities Patched in FreeRDP
[caption id="" align="aligncenter" width="400px"][/caption]
Related: Aerial Severity Flaws Patched in FreeXL Library
Related: Cipher Beheading Flaws Patched in HDF5 Library
[caption id="" align="aligncenter" width="400px"]
[/caption]
[caption id="" align="aligncenter" width="400px"]
[/caption]
[caption id="" align="aligncenter" width="400px"]
[/caption]
[caption id="" align="aligncenter" width="400px"]
[/caption]
[caption id="" align="aligncenter" width="400px"]
[/caption]
[caption id="" align="aligncenter" width="400px"]
[/caption]
[caption id="" align="aligncenter" width="400px"]

[/caption]
[caption id="" align="aligncenter" width="400px"]

[/caption]