Simple DirectMedia Layer contains two vulnerabilities that could an attacker to remotely execute code on the victims machine. Both bugs are present in the SDL2_image library, which is used for loading images in different formats. A specially crafted PCX file can lead to a heap buffer overflow and remote code execution in both cases. Cisco Talos worked with SDL to ensure that these issues are resolved and that an update is available for affected customers. (UPDATE: SDL released an additional update that fixes four additional vulnerabilities.)”]

