An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2 Security Advisory openeuler-security@openeuler.org openEuler security committee openEuler-SA-2021-1426 Final 1.0 1.0 2021-11-12 Initial 2021-11-12 2021-11-12 openEuler SA Tool V1.0 2021-11-12 SDL security update An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2. Simple DirectMedia Layer(SDL) is a cross-platform development library designed\ to provide low level access to audio, keyboard, mouse, joystick, and graphics\ hardware via OpenGL and Direct3D. It is used by video playback software, emulators,\ and popular games including Valve's award winning catalog and many Humble Bundle games.\ Security Fix(es): SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.(CVE-2019-7572) SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7574) SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7575) An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2. openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section. High SDL https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7572 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7574 https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7575 https://nvd.nist.gov/vuln/detail/CVE-2019-7572 https://nvd.nist.gov/vuln/detail/CVE-2019-7574 https://nvd.nist.gov/vuln/detail/CVE-2019-7575 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 SDL-debugsource-1.2.15-39.oe1.aarch64.rpm SDL-1.2.15-39.oe1.aarch64.rpm SDL-help-1.2.15-39.oe1.aarch64.rpm SDL-devel-1.2.15-39.oe1.aarch64.rpm SDL-debuginfo-1.2.15-39.oe1.aarch64.rpm SDL-debugsource-1.2.15-39.oe1.aarch64.rpm SDL-devel-1.2.15-39.oe1.aarch64.rpm SDL-1.2.15-39.oe1.aarch64.rpm SDL-debuginfo-1.2.15-39.oe1.aarch64.rpm SDL-help-1.2.15-39.oe1.aarch64.rpm SDL-1.2.15-39.oe1.src.rpm SDL-1.2.15-39.oe1.src.rpm SDL-help-1.2.15-39.oe1.x86_64.rpm SDL-devel-1.2.15-39.oe1.x86_64.rpm SDL-debuginfo-1.2.15-39.oe1.x86_64.rpm SDL-1.2.15-39.oe1.x86_64.rpm SDL-debugsource-1.2.15-39.oe1.x86_64.rpm SDL-devel-1.2.15-39.oe1.x86_64.rpm SDL-debuginfo-1.2.15-39.oe1.x86_64.rpm SDL-help-1.2.15-39.oe1.x86_64.rpm SDL-debugsource-1.2.15-39.oe1.x86_64.rpm SDL-1.2.15-39.oe1.x86_64.rpm SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c. 2021-11-12 CVE-2019-7572 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 High 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H SDL security update 2021-11-12 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c. 2021-11-12 CVE-2019-7574 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 High 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H SDL security update 2021-11-12 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c. 2021-11-12 CVE-2019-7575 openEuler-20.03-LTS-SP1 openEuler-20.03-LTS-SP2 High 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H SDL security update 2021-11-12 https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426