A security vulnerability has been discovered in SDL2, the Simple DirectMedia Layer library. This issue is related to memory leak, which might result in a denial of service. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4382-1
Multiple vulnerabilities have been found in libsdl2, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202305-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libsdl2: Multiple Vulnerabilities Date: May 03, 2023 Bugs: #836665, #890614 ID: 202305-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libsdl2, the worst of which could result in arbitrary code execution. Background ========= Simple DirectMedia Layer is a cross-platform development library designed to provide low level access to audio, keyboard, mouse, joystick, and graphics hardware via OpenGL and Direct3D. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libsdl2 < 2.26.0 > = 2.26.0 Description ========== Multiple vulnerabilities have been discovered in libsdl2. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libsdl2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libsdl2-2.26.0" References ========= [ 1 ] CVE-2021-33657 https://nvd.nist.gov/vuln/detail/CVE-2021-33657 [ 2 ] CVE-2022-4743 https://nvd.nist.gov/vuln/detail/CVE-2022-4743 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202305-18 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Several security vulnerabilities have been discovered in SDL2, the Simple DirectMedia Layer library. These vulnerabilities may allow an attacker to cause a denial of service or result in the execution of arbitrary code if malformed images or sound files are processed. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3314-1
A vulnerability has been fixed in libsdl2, the newer version of the Simple DirectMedia Layer library that provides low level access to audio, keyboard, mouse, joystick, and graphics hardware. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2803-1
Multiple vulnerabilities have been found in libsdl2, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-55 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: SDL 2: Multiple vulnerabilities Date: July 24, 2021 Bugs: #766204 ID: 202107-55 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libsdl2, the worst of which could result in a Denial of Service condition. Background ========= Simple DirectMedia Layer is a cross-platform development library designed to provide low level access to audio, keyboard, mouse, joystick, and graphics hardware via OpenGL and Direct3D. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libsdl2 < 2.0.14-r1 > = 2.0.14-r1 Description ========== Multiple vulnerabilities have been discovered in SDL 2. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All SDL 2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libsdl2-2.0.14-r1" References ========= [ 1 ] CVE-2020-14409 https://nvd.nist.gov/vuln/detail/CVE-2020-14409 [ 2 ] CVE-2020-14410 https://nvd.nist.gov/vuln/detail/CVE-2020-14410 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-55 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Several issues have been found in libsdl2, a library for portable low level access to a video framebuffer, audio output, mouse, and keyboard. All issues are related to either buffer overflow, integer overflow or . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2536-1
The update of libsdl2 released as DLA 1714-1 led to several regressions, as reported by Avital Ostromich. These regressions are caused by libsdl1.2 patches for CVE-2019-7637, CVE-2019-7635, CVE-2019-7638 and CVE-2019-7636 being applied to libsdl2 without adaptations. . Package : libsdl2 Version : 2.0.2+dfsg1-6+deb8u2 CVE ID : CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CVE-2019-7575 CVE-2019-7576 CVE-2019-7577 CVE-2019-7578 CVE-2019-7635 CVE-2019-7636 CVE-2019-7637 CVE-2019-7638 The update of libsdl2 released as DLA 1714-1 led to several regressions, as reported by Avital Ostromich. These regressions are caused by libsdl1.2 patches for CVE-2019-7637, CVE-2019-7635, CVE-2019-7638 and CVE-2019-7636 being applied to libsdl2 without adaptations. For Debian 8 "Jessie", this problem has been fixed in version 2.0.2+dfsg1-6+deb8u2. We recommend that you upgrade your libsdl2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Patch notes for libsdl2 correcting issues introduced by previous updates. Please update to version 2.0.2+dfsg1-6+deb8u2 to resolve these problems.. libsdl2 Update, Debian Security, Regression Fix, Software Patch. . Severity: Critical. LinuxSecurity.com Team
Multiple buffer overflow security issues have been found in libsdl2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard. . Package : libsdl2 Version : 2.0.2+dfsg1-6+deb8u1 CVE ID : CVE-2019-7572 CVE-2019-7573 CVE-2019-7574 CVE-2019-7575 CVE-2019-7576 CVE-2019-7577 CVE-2019-7578 CVE-2019-7635 CVE-2019-7636 CVE-2019-7637 CVE-2019-7638 Multiple buffer overflow security issues have been found in libsdl2, a library that allows low level access to a video frame buffer, audio output, mouse, and keyboard. For Debian 8 "Jessie", these problems have been fixed in version 2.0.2+dfsg1-6+deb8u1. We recommend that you upgrade your libsdl2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian 9 "Stretch" addresses various security vulnerabilities in libsdl2 with the package version 2.0.5+dfsg1-3+deb9u1 update.. Security Update, Debian LTS, Buffer Overflow, Libsdl2, Software Upgrade. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.