Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 6 MGASA-2018-0454 Moderate: SDL2_image Code Exec Threats

mageia
Calendar Grey November 17, 2018
Dist Mageia Esm H88
The recent Mageia security patch MGASA-2018-0454 tackles various vulnerabilities in SDL2_image, mitigating potential code execution risks.
This update fixes various security vulnerabilities affecting the SDL2_image library, listed below

Summary

This update fixes various security vulnerabilities affecting the SDL2_image library, listed below. The fixes are provided in SDL2_image 2.0.4, which depends on SDL2 2.0.8 or later. As such, the SDL2 and SDL2_mixer libraries are also updated to their current stable releases, providing various bug fixes and features.
The security vulnerabilities fixed in this update are the following:
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. (TALOS-2017-0488, CVE-2017-12122)
An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. (TALOS-2017-04...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=22769

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0488

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0489

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0490

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0491

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0497

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0498

- https://talosintelligence.com/vulnerability_reports/TALOS-2017-0499

- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0519

- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0520

- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0521

- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0645

- https://github.com/libsdl-org/SDL/blob/c49ecf6f7c10b668ebd87b89dfc3c7bfd215cb75/WhatsNew.txt

- https://www.libsdl.org/projects/SDL_image/

- https://www.libsdl.org/projects/SDL_mixer/

- https://www.cve.org/CVERecord?id=CVE-2017-12122

- https://www.cve.org/CVERecord?id=CVE-2017-14440

- https://www.cve.org/CVERecord?id=CVE-2017-14441

- https://www.cve.org/CVERecord?id=CVE-2017-14442

- https://www.cve.org/CVERecord?id=CVE-2017-14448

- https://www.cve.org/CVERecord?id=CVE-2017-14449

- https://www.cve.org/CVERecord?id=CVE-2017-14450

- https://www.cve.org/CVERecord?id=CVE-2018-3837

- https://www.cve.org/CVERecord?id=CVE-2018-3838

- https://www.cve.org/CVERecord?id=CVE-2018-3839

- https://www.cve.org/CVERecord?id=CVE-2018-3977

Resolution

SRPMS

- 6/core/sdl2-2.0.9-1.mga6

- 6/core/sdl2_image-2.0.4-1.mga6

- 6/core/sdl2_mixer-2.0.4-1.mga6

- 6/core/mingw-SDL2-2.0.9-1.mga6

- 6/core/mingw-SDL2_image-2.0.4-1.mga6

- 6/core/mingw-SDL2_mixer-2.0.4-1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 17 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0454.html
Type: security
CVE: CVE-2017-12122, CVE-2017-14440, CVE-2017-14441, CVE-2017-14442, CVE-2017-14448, CVE-2017-14449, CVE-2017-14450, CVE-2018-3837, CVE-2018-3838, CVE-2018-3839, CVE-2018-3977

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here