An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2021-1426
Final
1.0
1.0
2021-11-12
Initial
2021-11-12
2021-11-12
openEuler SA Tool V1.0
2021-11-12
SDL security update
An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2.
Simple DirectMedia Layer(SDL) is a cross-platform development library designed\ to provide low level access to audio, keyboard, mouse, joystick, and graphics\ hardware via OpenGL and Direct3D. It is used by video playback software, emulators,\ and popular games including Valve's award winning catalog and many Humble Bundle games.\
Security Fix(es):
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.(CVE-2019-7572)
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7574)
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7575)
An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
SDL
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7572
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7574
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7575
https://nvd.nist.gov/vuln/detail/CVE-2019-7572
https://nvd.nist.gov/vuln/detail/CVE-2019-7574
https://nvd.nist.gov/vuln/detail/CVE-2019-7575
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
SDL-debugsource-1.2.15-39.oe1.aarch64.rpm
SDL-1.2.15-39.oe1.aarch64.rpm
SDL-help-1.2.15-39.oe1.aarch64.rpm
SDL-devel-1.2.15-39.oe1.aarch64.rpm
SDL-debuginfo-1.2.15-39.oe1.aarch64.rpm
SDL-debugsource-1.2.15-39.oe1.aarch64.rpm
SDL-devel-1.2.15-39.oe1.aarch64.rpm
SDL-1.2.15-39.oe1.aarch64.rpm
SDL-debuginfo-1.2.15-39.oe1.aarch64.rpm
SDL-help-1.2.15-39.oe1.aarch64.rpm
SDL-1.2.15-39.oe1.src.rpm
SDL-1.2.15-39.oe1.src.rpm
SDL-help-1.2.15-39.oe1.x86_64.rpm
SDL-devel-1.2.15-39.oe1.x86_64.rpm
SDL-debuginfo-1.2.15-39.oe1.x86_64.rpm
SDL-1.2.15-39.oe1.x86_64.rpm
SDL-debugsource-1.2.15-39.oe1.x86_64.rpm
SDL-devel-1.2.15-39.oe1.x86_64.rpm
SDL-debuginfo-1.2.15-39.oe1.x86_64.rpm
SDL-help-1.2.15-39.oe1.x86_64.rpm
SDL-debugsource-1.2.15-39.oe1.x86_64.rpm
SDL-1.2.15-39.oe1.x86_64.rpm
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
2021-11-12
CVE-2019-7572
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
High
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SDL security update
2021-11-12
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
2021-11-12
CVE-2019-7574
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
High
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SDL security update
2021-11-12
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
2021-11-12
CVE-2019-7575
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
High
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SDL security update
2021-11-12
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426