Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2019:2463-2 Moderate: Buffer Problems in SDL2 Encountered

suse
Calendar Grey July 7, 2020
Dist Suse Esm H88
Addresses two vulnerabilities in SDL2 for SUSE Linux Enterprise Module. Moderately critical. Details for update provided.
An update that fixes two vulnerabilities is now available

Summary

This update for SDL2 fixes the following issues: Security issues fixed: - CVE-2019-13616: Fixed heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c (bsc#1141844). - CVE-2019-13626: Fixed integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c (bsc#1142031). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP1-2020-1866=1 Package List: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 (x86_64): SDL2-debugsource-2.0.8-3.15.1 libSDL2-2_0-0-32bit-2.0.8-3.15.1

References

#1141844 #1142031

Cross- CVE-2019-13616 CVE-2019-13626

Affected Products:

SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1

https://www.suse.com/security/cve/CVE-2019-13616.html

https://www.suse.com/security/cve/CVE-2019-13626.html

https://bugzilla.suse.com/1141844

https://bugzilla.suse.com/1142031

Announcement ID: SUSE-SU-2019:2463-2
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here