yocto ▾
›
master ▾
›
vulnerability
›
CVE-2019-7577
Component Overview
Vulnerability Overview
Name
CVE-2019-7577
Source
NVD (
link
)
Debian (
link
)
Description
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
CWEs
CWE-125
Published Date
Feb 7, 2019
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00063.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00073.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00088.html
Mailing List
https://bugzilla.libsdl.org/show_bug.cgi?id=4492
Exploit
https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/03/msg00015.html
Mailing List
https://lists.debian.org/debian-lts-announce/2019/03/msg00016.html
Mailing List
https://lists.debian.org/debian-lts-announce/2019/10/msg00020.html
Mailing List
https://lists.debian.org/debian-lts-announce/2019/10/msg00021.html
Mailing List
https://lists.debian.org/debian-lts-announce/2021/01/msg00024.html
Mailing List
https://lists.debian.org/debian-lts-announce/2021/10/msg00032.html
Mailing List
https://security.gentoo.org/glsa/201909-07
Third Party Advisory
https://usn.ubuntu.com/4156-1/
Third Party Advisory
https://usn.ubuntu.com/4156-2/
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00063.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00073.html
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00088.html
Mailing List
https://bugzilla.libsdl.org/show_bug.cgi?id=4492
Exploit
https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2019/03/msg00015.html
Mailing List
https://lists.debian.org/debian-lts-announce/2019/03/msg00016.html
Mailing List
https://lists.debian.org/debian-lts-announce/2019/10/msg00020.html
Mailing List
https://lists.debian.org/debian-lts-announce/2019/10/msg00021.html
Mailing List
https://lists.debian.org/debian-lts-announce/2021/01/msg00024.html
Mailing List
https://lists.debian.org/debian-lts-announce/2021/10/msg00032.html
Mailing List
https://security.gentoo.org/glsa/201909-07
Third Party Advisory
https://usn.ubuntu.com/4156-1/
Third Party Advisory
https://usn.ubuntu.com/4156-2/
Third Party Advisory
Analysis
#
Affected Component
Analysis
libsdl
Exploitable
Vulnerability Ratings
#
8.8
CVSSv31
6.8
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
sdl
buildroot
2025.02.x
1.2.15
Exploitable
sdl2
buildroot
2025.02.x
2.30.12
Not Affected
sdl
buildroot
master
1.2.15
Exploitable
sdl2
buildroot
master
2.32.10
Not Affected
libsdl
yocto
kirkstone
1.2.15
Exploitable
libsdl2
yocto
kirkstone
2.0.20
Not Affected
libsdl
yocto
scarthgap
1.2.15
Exploitable
libsdl2
yocto
scarthgap
2.30.1
Not Affected