Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
It was discovered that a double-free in the encoder of libvpx, a multimedia library for the VP8 and VP9 video codecs, may result in denial of service and potentially the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5928-1
An update for SDL is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: SDL security update Advisory ID: RHSA-2019:4024-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:4024 Issue date: 2019-12-02 CVE Names: CVE-2019-14906 ==================================================================== 1. Summary: An update for SDL is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device. Security Fix(es): * SDL: CVE-2019-13616 not fixed in Red Hat Enterprise Linux 7 erratum RHSA-2019:3950 (CVE-2019-14906) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1777372 - CVE-2019-14906 SDL: CVE-2019-13616 not fixed in Red Hat Enterprise Linux 7 erratum RHSA-2019:3950 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: SDL-1.2.15-15.el7_7.src.rpm x86_64: SDL-1.2.15-15.el7_7.i686.rpm SDL-1.2.15-15.el7_7.x86_64.rpm SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm SDL-devel-1.2.15-15.el7_7.i686.rpm SDL-devel-1.2.15-15.el7_7.x86_64.rpm SDL-static-1.2.15-15.el7_7.i686.rpm SDL-static-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: SDL-1.2.15-15.el7_7.src.rpm x86_64: SDL-1.2.15-15.el7_7.i686.rpm SDL-1.2.15-15.el7_7.x86_64.rpm SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm SDL-devel-1.2.15-15.el7_7.i686.rpm SDL-devel-1.2.15-15.el7_7.x86_64.rpm SDL-static-1.2.15-15.el7_7.i686.rpm SDL-static-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: SDL-1.2.15-15.el7_7.src.rpm ppc64: SDL-1.2.15-15.el7_7.ppc.rpm SDL-1.2.15-15.el7_7.ppc64.rpm SDL-debuginfo-1.2.15-15.el7_7.ppc.rpm SDL-debuginfo-1.2.15-15.el7_7.ppc64.rpm SDL-devel-1.2.15-15.el7_7.ppc.rpm SDL-devel-1.2.15-15.el7_7.ppc64.rpm ppc64le: SDL-1.2.15-15.el7_7.ppc64le.rpm SDL-debuginfo-1.2.15-15.el7_7.ppc64le.rpm SDL-devel-1.2.15-15.el7_7.ppc64le.rpm s390x: SDL-1.2.15-15.el7_7.s390.rpm SDL-1.2.15-15.el7_7.s390x.rpm SDL-debuginfo-1.2.15-15.el7_7.s390.rpm SDL-debuginfo-1.2.15-15.el7_7.s390x.rpm SDL-devel-1.2.15-15.el7_7.s390.rpm SDL-devel-1.2.15-15.el7_7.s390x.rpm x86_64: SDL-1.2.15-15.el7_7.i686.rpm SDL-1.2.15-15.el7_7.x86_64.rpm SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm SDL-devel-1.2.15-15.el7_7.i686.rpm SDL-devel-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: SDL-debuginfo-1.2.15-15.el7_7.ppc.rpm SDL-debuginfo-1.2.15-15.el7_7.ppc64.rpm SDL-static-1.2.15-15.el7_7.ppc.rpm SDL-static-1.2.15-15.el7_7.ppc64.rpm ppc64le: SDL-debuginfo-1.2.15-15.el7_7.ppc64le.rpm SDL-static-1.2.15-15.el7_7.ppc64le.rpm s390x: SDL-debuginfo-1.2.15-15.el7_7.s390.rpm SDL-debuginfo-1.2.15-15.el7_7.s390x.rpm SDL-static-1.2.15-15.el7_7.s390.rpm SDL-static-1.2.15-15.el7_7.s390x.rpm x86_64: SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm SDL-static-1.2.15-15.el7_7.i686.rpm SDL-static-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: SDL-1.2.15-15.el7_7.src.rpm x86_64: SDL-1.2.15-15.el7_7.i686.rpm SDL-1.2.15-15.el7_7.x86_64.rpm SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm SDL-devel-1.2.15-15.el7_7.i686.rpm SDL-devel-1.2.15-15.el7_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: SDL-debuginfo-1.2.15-15.el7_7.i686.rpm SDL-debuginfo-1.2.15-15.el7_7.x86_64.rpm SDL-static-1.2.15-15.el7_7.i686.rpm SDL-static-1.2.15-15.el7_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how toverify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-14906 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/errata/RHSA-2019:3950 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXeTbgNzjgjWX9erEAQgR9Q/9G1mkK5ELkM49YepX30GhjsaDASCq656D Yid+IE5WK5/4FLWyTDTjhoUGvX1iZHaZgrYvl6ih/4+vTbLMtfSbjPzTOFvg+oqe oKnQ027OWfWRJjGgBHHWuFOPQpu6tVKZPlTREBXvtnMmftj20zGVd++iHKU/gvyu TUZ892MjYBBFaUBCh6NhFGLhoP3x6cC/jHRvKPoEIX2wRShaCTUt6rYqwCFGTRJs 0AeK+8qQcn8Z4LStHgDueNrSvRxp2ZVwfNaTLkxyel4dj1upw5sM2azO/qO/AEZk C5LrMERwU0jyZN0BiovPAwitE1i31ZKccEBpf5lSXTyxmLpHT8lEsg7b0akMI0Ec +LrorAgDSixlfuqKPSrt3dEtseWd4hs1mvmPmZ51zupVpmdSH9/GmW/La0viPNn2 odEax6RTeJGkvOuPqJRjOynB6uTmR+cLBlVb1RrkHIJJHukmSfjbKNg4dV8POr0a yu0TsSF/59AT3EIkVKVHCABEuUFuzqa/2NnHVForsWdzx5yr7tbl/0EOS/HOmYVX 3q/TwZLIjgLj8KaYtCtUAe4WAoIie6FbSedrde8PQLdj9Lh+AJ9eqjHtDA7ESkER GKWICWN/V348gVhEVRhsxNtTrwZmAjNB679fChdl1PGt3HtAgOQ/59shH01pPvQA /jCShWu+arE=PqkN -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Multiple security issues were found in libvpx multimedia library which could result in denial of service and potentially the execution of arbitrary code if malformed WebM files are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4578-1
Update to 2.0.10 to fix security issues.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-8ef33a69ca 2019-10-10 16:18:53.545375 --------------------------------------------------------------------------------Name : SDL2 Product : Fedora 29 Version : 2.0.10 Release : 1.fc29 URL : http://www.libsdl.org/ Summary : Cross-platform multimedia library Description : Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device. --------------------------------------------------------------------------------Update Information: Update to 2.0.10 to fix security issues. --------------------------------------------------------------------------------ChangeLog: * Fri Jul 26 2019 Pete Walter - 2.0.10-1 - Update to 2.0.10 * Wed Jul 24 2019 Fedora Release Engineering - 2.0.9-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri Feb 15 2019 Tom Callaway - 2.0.9-3 - use khrplatform defines, not ptrdiff_t * Thu Jan 31 2019 Fedora Release Engineering - 2.0.9-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Fri Nov 2 2018 Tom Callaway - 2.0.9-1 - update to 2.0.9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1747237 - CVE-2019-13616 SDL: heap-based buffer overflow in SDL blit functions in video/SDL_blit*.c https://bugzilla.redhat.com/show_bug.cgi?id=1747237 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-8ef33a69ca' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-f5558abfef 2019-09-14 16:29:06.038565 --------------------------------------------------------------------------------Name : SDL Product : Fedora 31 Version : 1.2.15 Release : 42.fc31 URL : https://www.libsdl.org/ Summary : A cross-platform multimedia library Description : Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device. --------------------------------------------------------------------------------Update Information: This release fixes a heap buffer over-read in BlitNtoN() function when processing an invalid BMP image. --------------------------------------------------------------------------------References: [ 1 ] Bug #1747237 - CVE-2019-13616 SDL: Heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c https://bugzilla.redhat.com/show_bug.cgi?id=1747237 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-f5558abfef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This release fixes a buffer overflow when processing RIFF/WAV files with in invalid MS ADPCM predictor.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-9ef30a3636 2019-03-29 19:07:28.731769 --------------------------------------------------------------------------------Name : SDL Product : Fedora 30 Version : 1.2.15 Release : 38.fc30 URL : http://www.libsdl.org/ Summary : A cross-platform multimedia library Description : Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device. --------------------------------------------------------------------------------Update Information: This release fixes a buffer overflow when processing RIFF/WAV files with in invalid MS ADPCM predictor. --------------------------------------------------------------------------------References: [ 1 ] Bug #1676509 - CVE-2019-7577 SDL: Buffer over-read in function SDL_LoadWAV_RW in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676509 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-9ef30a3636' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This release fixes a buffer overflow when processing RIFF/WAV files with in invalid MS ADPCM predictor.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-bf531902c8 2019-03-19 05:15:20.144155 --------------------------------------------------------------------------------Name : SDL Product : Fedora 29 Version : 1.2.15 Release : 37.fc29 URL : http://www.libsdl.org/ Summary : A cross-platform multimedia library Description : Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device. --------------------------------------------------------------------------------Update Information: This release fixes a buffer overflow when processing RIFF/WAV files with in invalid MS ADPCM predictor. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 12 2019 Petr Pisar - 1.2.15-37 - Fix CVE-2019-7577 completely (a buffer overread in MS_ADPCM_nibble and MS_ADPCM_decode on an invalid predictor) (bug #1676510) * Fri Feb 15 2019 Petr Pisar - 1.2.15-36 - Fix CVE-2019-7577 (a buffer overread in MS_ADPCM_decode) (bug #1676510) - Fix CVE-2019-7575 (a buffer overwrite in MS_ADPCM_decode) (bug #1676744) - Fix CVE-2019-7574 (a buffer overread in IMA_ADPCM_decode) (bug #1676750) - Fix CVE-2019-7572 (a buffer overread in IMA_ADPCM_nibble) (bug #1676754) - Fix CVE-2019-7572 (a buffer overwrite in IMA_ADPCM_nibble) (bug #1676754) - Fix CVE-2019-7573, CVE-2019-7576 (buffer overreads in InitMS_ADPCM) (bugs #1676752, #1676756) - Fix CVE-2019-7578 (a buffer overread in InitIMA_ADPCM) (bug #1676782) - Fix CVE-2019-7638, CVE-2019-7636 (buffer overflows when processing BMP images with too high number of colors) (bugs #1677144, #1677157) - Fix CVE-2019-7637 (an integer overflow in SDL_CalculatePitch) (bug #1677152) - Fix CVE-2019-7635 (a buffer overread when blitting aBMP image with pixel colors out the palette) (bug #1677159) - Reject 2, 3, 5, 6, 7-bpp BMP images (bug #1677159) * Mon Jan 14 2019 Petr Pisar - 1.2.15-35 - Remove manual updating of config.{guess,sub} - this has been part of %configure since 2013 - Use system glext.h to prevent from clashing on a GL_GLEXT_VERSION definition (bug #1662778) * Tue Aug 28 2018 Petr Pisar - 1.2.15-34 - Remove useless build-time dependency on audiofile-devel --------------------------------------------------------------------------------References: [ 1 ] Bug #1676509 - CVE-2019-7577 SDL: Buffer over-read in function SDL_LoadWAV_RW in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676509 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-bf531902c8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-7a554204c1 2019-02-26 03:04:46.115334 --------------------------------------------------------------------------------Name : SDL Product : Fedora 29 Version : 1.2.15 Release : 36.fc29 URL : http://www.libsdl.org/ Summary : A cross-platform multimedia library Description : Simple DirectMedia Layer (SDL) is a cross-platform multimedia library designed to provide fast access to the graphics frame buffer and audio device. --------------------------------------------------------------------------------Update Information: This release fixes various buffer overflows when parsing or processing damaged Waveform audio and BMP image files. --------------------------------------------------------------------------------ChangeLog: * Fri Feb 15 2019 Petr Pisar - 1.2.15-36 - Fix CVE-2019-7577 (a buffer overread in MS_ADPCM_decode) (bug #1676510) - Fix CVE-2019-7575 (a buffer overwrite in MS_ADPCM_decode) (bug #1676744) - Fix CVE-2019-7574 (a buffer overread in IMA_ADPCM_decode) (bug #1676750) - Fix CVE-2019-7572 (a buffer overread in IMA_ADPCM_nibble) (bug #1676754) - Fix CVE-2019-7572 (a buffer overwrite in IMA_ADPCM_nibble) (bug #1676754) - Fix CVE-2019-7573, CVE-2019-7576 (buffer overreads in InitMS_ADPCM) (bugs #1676752, #1676756) - Fix CVE-2019-7578 (a buffer overread in InitIMA_ADPCM) (bug #1676782) - Fix CVE-2019-7638, CVE-2019-7636 (buffer overflows when processing BMP images with too high number of colors) (bugs #1677144, #1677157) - Fix CVE-2019-7637 (an integer overflow in SDL_CalculatePitch) (bug #1677152) - Fix CVE-2019-7635 (a buffer overread when blitting a BMP image with pixel colors out the palette) (bug #1677159) - Reject 2, 3, 5, 6, 7-bpp BMP images (bug #1677159) * Mon Jan 14 2019 Petr Pisar -1.2.15-35 - Remove manual updating of config.{guess,sub} - this has been part of %configure since 2013 - Use system glext.h to prevent from clashing on a GL_GLEXT_VERSION definition (bug #1662778) * Tue Aug 28 2018 Petr Pisar - 1.2.15-34 - Remove useless build-time dependency on audiofile-devel --------------------------------------------------------------------------------References: [ 1 ] Bug #1676509 - CVE-2019-7577 SDL: Buffer over-read in function SDL_LoadWAV_RW in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676509 [ 2 ] Bug #1676743 - CVE-2019-7575 SDL: Heap based buffer overflow in function MS_ADPCM_decode in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676743 [ 3 ] Bug #1676749 - CVE-2019-7574 SDL: heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676749 [ 4 ] Bug #1676753 - CVE-2019-7572 SDL: Buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676753 [ 5 ] Bug #1676751 - CVE-2019-7573 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676751 [ 6 ] Bug #1676755 - CVE-2019-7576 SDL: heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676755 [ 7 ] Bug #1676781 - CVE-2019-7578 SDL: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c https://bugzilla.redhat.com/show_bug.cgi?id=1676781 [ 8 ] Bug #1677143 - CVE-2019-7638 SDL: heap-based buffer over-read in Map1toN in video/SDL_pixels.c https://bugzilla.redhat.com/show_bug.cgi?id=1677143 [ 9 ] Bug #1677156 - CVE-2019-7636 SDL: heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c https://bugzilla.redhat.com/show_bug.cgi?id=1677156 [ 10 ] Bug #1677151 - CVE-2019-7637 SDL: heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c https://bugzilla.redhat.com/show_bug.cgi?id=1677151 [ 11 ] Bug #1677158 - CVE-2019-7635 SDL: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c https://bugzilla.redhat.com/show_bug.cgi?id=1677158 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-7a554204c1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.