Lucene search

K
suseSuseOPENSUSE-SU-2019:2109-1
HistorySep 10, 2019 - 12:00 a.m.

Security update for SDL_image (moderate)

2019-09-1000:00:00
lists.opensuse.org
117

0.005 Low

EPSS

Percentile

75.7%

An update that fixes 7 vulnerabilities is now available.

Description:

This update for SDL_image fixes the following issues:

Update SDL_Image to new snapshot 1.2.12+hg695.

Security issues fixed:

  • TALOS-2019-0821 CVE-2019-5052: exploitable integer overflow
    vulnerability when loading a PCX file (boo#1140421)
  • TALOS-2019-0841 CVE-2019-5057: code execution vulnerability in the PCX
    image-rendering functionality of SDL2_image (boo#1143763)
  • TALOS-2019-0842 CVE-2019-5058: heap overflow in XCF image rendering can
    lead to code execution (boo#1143764)
  • TALOS-2019-0843 CVE-2019-5059: heap overflow in XPM image handling
    (boo#1143766)
  • TALOS-2019-0844 CVE-2019-5060: integer overflow in the XPM image
    (boo#1143768)
  • CVE-2019-7635: heap-based buffer over-read in Blit1to4 in
    video/SDL_blit_1.c (boo#1124827)
  • CVE-2019-13616: fix heap buffer overflow when reading a crafted bmp file
    (boo#1141844).

This update was imported from the openSUSE:Leap:15.0:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Backports SLE-15-SP1:

    zypper in -t patch openSUSE-2019-2109=1

  • openSUSE Backports SLE-15:

    zypper in -t patch openSUSE-2019-2109=1

OSVersionArchitecturePackageVersionFilename
openSUSE Backports SLE15-SP1aarch64- opensuse backports sle< 15-SP1 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):.aarch64.rpm
openSUSE Backports SLE15-SP1ppc64le- opensuse backports sle< 15-SP1 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):.ppc64le.rpm
openSUSE Backports SLE15-SP1s390x- opensuse backports sle< 15-SP1 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):.s390x.rpm
openSUSE Backports SLE15-SP1x86_64- opensuse backports sle< 15-SP1 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64):.x86_64.rpm
openSUSE Backports SLE15-SP1aarch64_ilp32- opensuse backports sle< 15-SP1 (aarch64_ilp32):- openSUSE Backports SLE-15-SP1 (aarch64_ilp32):.aarch64_ilp32.rpm
openSUSE Backports SLE15aarch64<  openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):.aarch64.rpm
openSUSE Backports SLE15ppc64le<  openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):.ppc64le.rpm
openSUSE Backports SLE15s390x<  openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):.s390x.rpm
openSUSE Backports SLE15x86_64<  openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):- openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64):.x86_64.rpm
openSUSE Backports SLE15aarch64_ilp32<  openSUSE Backports SLE-15 (aarch64_ilp32):- openSUSE Backports SLE-15 (aarch64_ilp32):.aarch64_ilp32.rpm