1 |
type: security |
2 |
subject: Updated SDL12 packages fix security vulnerability |
3 |
CVE: |
4 |
- CVE-2019-7572 |
5 |
- CVE-2019-7573 |
6 |
- CVE-2019-7574 |
7 |
- CVE-2019-7575 |
8 |
- CVE-2019-7577 |
9 |
- CVE-2019-7635 |
10 |
- CVE-2019-7637 |
11 |
- CVE-2019-7638 |
12 |
src: |
13 |
6: |
14 |
core: |
15 |
- SDL12-1.2.15-19.1.mga6 |
16 |
- mingw-SDL-1.2.15-8.1.mga6 |
17 |
description: | |
18 |
This release fixes various buffer overflows when parsing or processing |
19 |
damaged Waveform audio and BMP image files. |
20 |
- Fix CVE-2019-7577 (a buffer overread in MS_ADPCM_decode) (rhbz#1676510) |
21 |
- Fix CVE-2019-7575 (a buffer overwrite in MS_ADPCM_decode) (rhbz#1676744) |
22 |
- Fix CVE-2019-7574 (a buffer overread in IMA_ADPCM_decode) (rhbz#1676750) |
23 |
- Fix CVE-2019-7572 (a buffer overread in IMA_ADPCM_nibble) (rhbz#1676754) |
24 |
- Fix CVE-2019-7572 (a buffer overwrite in IMA_ADPCM_nibble) (rhbz#1676754) |
25 |
- Fix CVE-2019-7573, CVE-2019-7576 (buffer overreads in InitMS_ADPCM) |
26 |
(rhbz#1676752, rhbz#1676756) |
27 |
- Fix CVE-2019-7578 (a buffer overread in InitIMA_ADPCM) (rhbz#1676782) |
28 |
- Fix CVE-2019-7638, CVE-2019-7636 (buffer overflows when processing BMP |
29 |
images with too high number of colors) (rhbz#1677144, rhbz#1677157) |
30 |
- Fix CVE-2019-7637 (an integer overflow in SDL_CalculatePitch) |
31 |
(rhbz#1677152) |
32 |
- Fix CVE-2019-7635 (a buffer overread when blitting a BMP image with pixel |
33 |
colors out the palette) (rhbz#1677159) |
34 |
- Reject 2, 3, 5, 6, 7-bpp BMP images (rhbz#1677159) |
35 |
references: |
36 |
- https://bugs.mageia.org/show_bug.cgi?id=24496 |
37 |
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/OHEXXGCOKNICFBDMNVYYDTSDLQ42K5G5/ |
38 |
ID: MGASA-2019-0127 |