CVE-2017-2888 is an integer overflow vulnerability in SDL 2.0.5, affecting various Canonical and Debian Linux distributions and the Simple DirectMedia Layer library. This flaw occurs when creating an RGB Surface, where a specially crafted image file can lead to insufficient memory allocation, a subsequent buffer overflow, and potential arbitrary code execution. With a CVSS score of 8.8 (HIGH), it presents a significant risk, requiring user interaction (UI:R) but with low attack complexity (AC:L) over a network (AV:N), potentially leading to high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.5CPE matchmatch criteria | cpe:2.3:a:libsdl:simple_directmedia_layer:2.0.5:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
19.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.