Candidate: CVE-2019-5058 PublicDate: 2019-07-31 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5058 https://talosintelligence.com/vulnerability_reports/TALOS-2019-0842 Description: An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libsdl2-image: upstream_libsdl2-image: released (2.0.5+dfsg1-1, 2.0.4+dfsg1-1+deb10u1, 2.0.1+dfsg-2+deb9u2, 2.0.0+dfsg-3+deb8u2) precise/esm_libsdl2-image: DNE trusty_libsdl2-image: ignored (out of standard support) trusty/esm_libsdl2-image: DNE xenial_libsdl2-image: ignored (end of standard support, was needed) bionic_libsdl2-image: needed disco_libsdl2-image: ignored (reached end-of-life) eoan_libsdl2-image: released (2.0.5+dfsg1-1) focal_libsdl2-image: released (2.0.5+dfsg1-1) groovy_libsdl2-image: released (2.0.5+dfsg1-1) hirsute_libsdl2-image: released (2.0.5+dfsg1-1) impish_libsdl2-image: released (2.0.5+dfsg1-1) jammy_libsdl2-image: released (2.0.5+dfsg1-1) devel_libsdl2-image: released (2.0.5+dfsg1-1)