CVE-2020-14409 describes an Integer Overflow vulnerability in SDL (Simple DirectMedia Layer) versions through 2.0.12, specifically within the SDL_BlitCopy function, which can lead to heap corruption when processing a specially crafted .BMP file. This vulnerability affects products utilizing SDL, including Debian, FedoraProject, libsdl, and StarWindSoftware. With a CVSS score of 7.8 (High), this vulnerability requires user interaction (UI:R) and local access (AV:L) to exploit, but successful exploitation could lead to high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The Faucet Risk Score is 58/100, indicating a moderate risk. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.12, <= 2.0.20CPE matchmatch criteria | cpe:2.3:a:libsdl:simple_directmedia_layer:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
v8CPE matchmatch criteria | cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build12533:*:*:*:vsphere:*:* | ||
v8CPE matchmatch criteria | cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8:build12658:*:*:*:vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.