CVE-2019-7577 is a buffer over-read vulnerability affecting Simple DirectMedia Layer (SDL) versions through 1.2.15 and 2.x through 2.0.9, specifically impacting the libsdl library and downstream Linux distributions such as Debian, Fedora, and Ubuntu. Rated with a CVSS score of 8.8 (High), this flaw allows unauthenticated remote attackers to compromise system confidentiality, integrity, and availability by tricking a user into processing a specially crafted WAV file. Despite a high risk score and elevated EPSS ranking, there are currently no known public exploits, active campaigns in the wild, or significant community discussions regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.15CPE matchmatch criteria | cpe:2.3:a:libsdl:simple_directmedia_layer:*:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.0.9CPE matchmatch criteria | cpe:2.3:a:libsdl:simple_directmedia_layer:*:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
42.3CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.