
CVE-2018-3839 – Gentoo Linux Security Advisory 201903-17
https://notcve.org/view.php?id=CVE-2018-3839
10 Apr 2018 — An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. Existe una vulnerabilidad explotable de ejecución de código en la funcionalidad de renderización de imágenes XCF de Simple DirectMedia Layer SDL2_image-2.0.2. Una imagen XCF especialmente ... • https://security.gentoo.org/glsa/201903-17 • CWE-787: Out-of-bounds Write •

CVE-2017-2887 – Debian Security Advisory 4184-1
https://notcve.org/view.php?id=CVE-2017-2887
11 Oct 2017 — An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability. Existe una vulnerabilidad explotable de desbordamiento de búfer en la funcionalidad de manejo de propiedades XCF de SDL_image 2.0.1. Un archivo xcf especialmente manipulado podría provocar un desbordamient... • http://www.securityfocus.com/bid/101215 • CWE-787: Out-of-bounds Write •