Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE: 2019:0950-1 Moderate: SDL2 Heap Overflow Fixes and Instructions

suse
Calendar Grey April 15, 2019
Dist Suse Esm H88
SUSE Security Patch for SDL2 resolves various vulnerabilities. Be sure to adhere to the specified update guidelines for safeguarding.
An update that fixes 11 vulnerabilities is now available

Summary

This update for SDL2 fixes the following issues: Security issues fixed: - CVE-2019-7572: Fixed a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.(bsc#1124806). - CVE-2019-7578: Fixed a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c (bsc#1125099). - CVE-2019-7576: Fixed heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (bsc#1124799). - CVE-2019-7573: Fixed a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (bsc#1124805). - CVE-2019-7635: Fixed a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c. (bsc#1124827). - CVE-2019-7636: Fixed a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c (bsc#1124826). - CVE-2019-7638: Fixed a heap-based buffer over-read in Map1toN in video/SDL_pixels.c (bsc#1124824).

References

#1124799 #1124800 #1124802 #1124803 #1124805

#1124806 #1124824 #1124825 #1124826 #1124827

#1125099

Cross- CVE-2019-7572 CVE-2019-7573 CVE-2019-7574

CVE-2019-7575 CVE-2019-7576 CVE-2019-7577

CVE-2019-7578 CVE-2019-7635 CVE-2019-7636

CVE-2019-7637 CVE-2019-7638

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2019-7572.html

https://www.suse.com/security/cve/CVE-2019-7573.html

https://www.suse.com/security/cve/CVE-2019-7574.html

https://www.suse.com/security/cve/CVE-2019-7575.html

https://www.suse.com/security/cve/CVE-2019-7576.html

https://www.suse.com/security/cve/CVE-2019-7577.html

https://www.suse.com/security/cve/CVE-2019-7578.html

Announcement ID: SUSE-SU-2019:0950-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here