Multiple vulnerabilities have been found in libsdl, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202305-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libsdl: Multiple Vulnerabilities Date: May 03, 2023 Bugs: #692388, #836665, #861809 ID: 202305-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libsdl, the worst of which could result in arbitrary code execution. Background ========= Simple DirectMedia Layer is a cross-platform development library designed to provide low level access to audio, keyboard, mouse, joystick, and graphics hardware via OpenGL and Direct3D. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libsdl < 1.2.15_p20221201> = 1.2.15_p20221201 Description ========== Multiple vulnerabilities have been discovered in SDL. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libsdl users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libsdl-1.2.15_p20221201" References ========= [ 1 ] CVE-2019-7572 https://nvd.nist.gov/vuln/detail/CVE-2019-7572 [ 2 ] CVE-2019-7573 https://nvd.nist.gov/vuln/detail/CVE-2019-7573 [ 3 ] CVE-2019-7574 https://nvd.nist.gov/vuln/detail/CVE-2019-7574 [ 4 ] CVE-2019-7575 https://nvd.nist.gov/vuln/detail/CVE-2019-7575 [ 5 ] CVE-2019-7576 https://nvd.nist.gov/vuln/detail/CVE-2019-7576 [ 6 ] CVE-2019-7577 https://nvd.nist.gov/vuln/detail/CVE-2019-7577 [ 7 ] CVE-2019-7578 https://nvd.nist.gov/vuln/detail/CVE-2019-7578 [ 8 ] CVE-2019-7635 https://nvd.nist.gov/vuln/detail/CVE-2019-7635 [ 9 ] CVE-2019-7636 https://nvd.nist.gov/vuln/detail/CVE-2019-7636 [ 10 ] CVE-2019-7638 https://nvd.nist.gov/vuln/detail/CVE-2019-7638 [ 11 ] CVE-2019-13616 https://nvd.nist.gov/vuln/detail/CVE-2019-13616 [ 12 ] CVE-2021-33657 https://nvd.nist.gov/vuln/detail/CVE-2021-33657 [ 13 ] CVE-2022-34568 https://nvd.nist.gov/vuln/detail/CVE-2022-34568 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202305-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
SDL (Simple DirectMedia Layer) could be made to crash or run programs if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-5398-1 April 28, 2022 libsdl1.2, libsdl2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: SDL (Simple DirectMedia Layer) could be made to crash or run programs if it opened a specially crafted file. Software Description: - libsdl2: Cross-platform multimedia library with low access to hardware - libsdl1.2: Simple DirectMedia Layer Details: It was discovered that SDL (Simple DirectMedia Layer) incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: libsdl2-2.0-0 2.0.14+dfsg2-3ubuntu0.1 Ubuntu 18.04 LTS: libsdl1.2debian 1.2.15+dfsg2-0.1ubuntu0.2 Ubuntu 16.04 ESM: libsdl1.2debian 1.2.15+dfsg1-3ubuntu0.1+esm1 Ubuntu 14.04 ESM: libsdl1.2debian 1.2.15-8ubuntu1.1+esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5398-1 CVE-2021-33657 Package Information: https://launchpad.net/ubuntu/+source/libsdl2/2.0.14+dfsg2-3ubuntu0.1 https://launchpad.net/ubuntu/+source/libsdl1.2/1.2.15+dfsg2-0.1ubuntu0.2 . Uncover the SDL weakness present in Ubuntu systems which could lead to instabilities or permit unauthorized code execution.. SDL Vulnerability, Ubuntu Security Advisory, Code Execution Risk. . LinuxSecurity.com Team
Multiple buffer overflow security issues have been found in libsdl1.2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard. . Package : libsdl1.2 Version : 1.2.15-10+deb8u1 CVE ID : CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CVE-2019-7575 CVE-2019-7576 CVE-2019-7577 CVE-2019-7578 CVE-2019-7635 CVE-2019-7636 CVE-2019-7637 CVE-2019-7638 Multiple buffer overflow security issues have been found in libsdl1.2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard. For Debian 8 "Jessie", these problems have been fixed in version 1.2.15-10+deb8u1. We recommend that you upgrade your libsdl1.2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : libsdl1.2 Version : 1.2.15-10+deb8u1 CVE ID : CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CV. buffer, overflow, security, found, libsdl1, library, allows. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.