cvrf2cusa/cvrf/2021/cvrf-openEuler-SA-2021-1426.xml
Jia Chao 0b34274085 git mv
Signed-off-by: Jia Chao <jiac13@chinaunicom.cn>
2024-07-25 09:57:37 +08:00

189 lines
11 KiB
XML

<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
<DocumentTitle xml:lang="en">An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2</DocumentTitle>
<DocumentType>Security Advisory</DocumentType>
<DocumentPublisher Type="Vendor">
<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
<IssuingAuthority>openEuler security committee</IssuingAuthority>
</DocumentPublisher>
<DocumentTracking>
<Identification>
<ID>openEuler-SA-2021-1426</ID>
</Identification>
<Status>Final</Status>
<Version>1.0</Version>
<RevisionHistory>
<Revision>
<Number>1.0</Number>
<Date>2021-11-12</Date>
<Description>Initial</Description>
</Revision>
</RevisionHistory>
<InitialReleaseDate>2021-11-12</InitialReleaseDate>
<CurrentReleaseDate>2021-11-12</CurrentReleaseDate>
<Generator>
<Engine>openEuler SA Tool V1.0</Engine>
<Date>2021-11-12</Date>
</Generator>
</DocumentTracking>
<DocumentNotes>
<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">SDL security update</Note>
<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2.</Note>
<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">Simple DirectMedia Layer(SDL) is a cross-platform development library designed\ to provide low level access to audio, keyboard, mouse, joystick, and graphics\ hardware via OpenGL and Direct3D. It is used by video playback software, emulators,\ and popular games including Valve&apos;s award winning catalog and many Humble Bundle games.\
Security Fix(es):
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.(CVE-2019-7572)
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7574)
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7575)</Note>
<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for SDL is now available for openEuler-20.03-LTS-SP1 and openEuler-20.03-LTS-SP2.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">High</Note>
<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">SDL</Note>
</DocumentNotes>
<DocumentReferences>
<Reference Type="Self">
<URL>https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426</URL>
</Reference>
<Reference Type="openEuler CVE">
<URL>https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7572</URL>
<URL>https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7574</URL>
<URL>https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2019-7575</URL>
</Reference>
<Reference Type="Other">
<URL>https://nvd.nist.gov/vuln/detail/CVE-2019-7572</URL>
<URL>https://nvd.nist.gov/vuln/detail/CVE-2019-7574</URL>
<URL>https://nvd.nist.gov/vuln/detail/CVE-2019-7575</URL>
</Reference>
</DocumentReferences>
<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
<Branch Type="Product Name" Name="openEuler">
<FullProductName ProductID="openEuler-20.03-LTS-SP1" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">openEuler-20.03-LTS-SP1</FullProductName>
<FullProductName ProductID="openEuler-20.03-LTS-SP2" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">openEuler-20.03-LTS-SP2</FullProductName>
</Branch>
<Branch Type="Package Arch" Name="aarch64">
<FullProductName ProductID="SDL-debugsource-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-debugsource-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-help-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-help-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-devel-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-devel-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-debuginfo-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-debuginfo-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-debugsource-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-debugsource-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-devel-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-devel-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-debuginfo-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-debuginfo-1.2.15-39.oe1.aarch64.rpm</FullProductName>
<FullProductName ProductID="SDL-help-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-help-1.2.15-39.oe1.aarch64.rpm</FullProductName>
</Branch>
<Branch Type="Package Arch" Name="src">
<FullProductName ProductID="SDL-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-1.2.15-39.oe1.src.rpm</FullProductName>
<FullProductName ProductID="SDL-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-1.2.15-39.oe1.src.rpm</FullProductName>
</Branch>
<Branch Type="Package Arch" Name="x86_64">
<FullProductName ProductID="SDL-help-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-help-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-devel-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-devel-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-debuginfo-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-debuginfo-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-debugsource-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP1">SDL-debugsource-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-devel-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-devel-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-debuginfo-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-debuginfo-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-help-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-help-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-debugsource-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-debugsource-1.2.15-39.oe1.x86_64.rpm</FullProductName>
<FullProductName ProductID="SDL-1.2.15-39" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP2">SDL-1.2.15-39.oe1.x86_64.rpm</FullProductName>
</Branch>
</ProductTree>
<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
<Notes>
<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.</Note>
</Notes>
<ReleaseDate>2021-11-12</ReleaseDate>
<CVE>CVE-2019-7572</CVE>
<ProductStatuses>
<Status Type="Fixed">
<ProductID>openEuler-20.03-LTS-SP1</ProductID>
<ProductID>openEuler-20.03-LTS-SP2</ProductID>
</Status>
</ProductStatuses>
<Threats>
<Threat Type="Impact">
<Description>High</Description>
</Threat>
</Threats>
<CVSSScoreSets>
<ScoreSet>
<BaseScore>8.8</BaseScore>
<Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
</ScoreSet>
</CVSSScoreSets>
<Remediations>
<Remediation Type="Vendor Fix">
<Description>SDL security update</Description>
<DATE>2021-11-12</DATE>
<URL>https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426</URL>
</Remediation>
</Remediations>
</Vulnerability>
<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
<Notes>
<Note Title="Vulnerability Description" Type="General" Ordinal="2" xml:lang="en">SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.</Note>
</Notes>
<ReleaseDate>2021-11-12</ReleaseDate>
<CVE>CVE-2019-7574</CVE>
<ProductStatuses>
<Status Type="Fixed">
<ProductID>openEuler-20.03-LTS-SP1</ProductID>
<ProductID>openEuler-20.03-LTS-SP2</ProductID>
</Status>
</ProductStatuses>
<Threats>
<Threat Type="Impact">
<Description>High</Description>
</Threat>
</Threats>
<CVSSScoreSets>
<ScoreSet>
<BaseScore>8.8</BaseScore>
<Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
</ScoreSet>
</CVSSScoreSets>
<Remediations>
<Remediation Type="Vendor Fix">
<Description>SDL security update</Description>
<DATE>2021-11-12</DATE>
<URL>https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426</URL>
</Remediation>
</Remediations>
</Vulnerability>
<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
<Notes>
<Note Title="Vulnerability Description" Type="General" Ordinal="3" xml:lang="en">SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.</Note>
</Notes>
<ReleaseDate>2021-11-12</ReleaseDate>
<CVE>CVE-2019-7575</CVE>
<ProductStatuses>
<Status Type="Fixed">
<ProductID>openEuler-20.03-LTS-SP1</ProductID>
<ProductID>openEuler-20.03-LTS-SP2</ProductID>
</Status>
</ProductStatuses>
<Threats>
<Threat Type="Impact">
<Description>High</Description>
</Threat>
</Threats>
<CVSSScoreSets>
<ScoreSet>
<BaseScore>8.8</BaseScore>
<Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
</ScoreSet>
</CVSSScoreSets>
<Remediations>
<Remediation Type="Vendor Fix">
<Description>SDL security update</Description>
<DATE>2021-11-12</DATE>
<URL>https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426</URL>
</Remediation>
</Remediations>
</Vulnerability>
</cvrfdoc>