Bug 1124800 - (CVE-2019-7577) VUL-1: CVE-2019-7577: SDL,SDL2: buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
(CVE-2019-7577)
VUL-1: CVE-2019-7577: SDL,SDL2: buffer over-read in SDL_LoadWAV_RW in audio/S...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/224386/
CVSSv2:NVD:CVE-2019-7577:6.8:(AV:N/AC...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-02-08 12:32 UTC by Robert Frohl
Modified: 2022-03-01 16:16 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Frohl 2019-02-08 12:32:07 UTC
CVE-2019-7577

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer
over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-7577
http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-7577.html
https://bugzilla.libsdl.org/show_bug.cgi?id=4492
https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
Comment 1 Robert Frohl 2019-02-21 14:57:27 UTC
all codestreams are affected I believe:
- SUSE:SLE-10-SP3:Update
- SUSE:SLE-11:Update
- SUSE:SLE-12:Update
- SUSE:SLE-15:Update 

For SLE15 both SDL and SDL2

upstream fix:
https://bugzilla.libsdl.org/attachment.cgi?id=3608&action=diff
Comment 3 Swamp Workflow Management 2019-02-27 15:23:29 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2019-03-13.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64214
Comment 10 Swamp Workflow Management 2019-03-29 23:18:40 UTC
SUSE-SU-2019:13998-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    SDL-1.2.13-106.11.1
SUSE Linux Enterprise Server 11-SP4 (src):    SDL-1.2.13-106.11.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    SDL-1.2.13-106.11.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    SDL-1.2.13-106.11.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2019-04-08 13:34:08 UTC
SUSE-SU-2019:0899-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP4 (src):    SDL-1.2.15-15.11.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    SDL-1.2.15-15.11.1
SUSE Linux Enterprise Server 12-SP4 (src):    SDL-1.2.15-15.11.1
SUSE Linux Enterprise Server 12-SP3 (src):    SDL-1.2.15-15.11.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    SDL-1.2.15-15.11.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    SDL-1.2.15-15.11.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2019-04-09 19:10:51 UTC
SUSE-SU-2019:0917-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    SDL-1.2.15-3.9.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2019-04-15 13:10:30 UTC
SUSE-SU-2019:0950-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    SDL2-2.0.8-3.9.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2019-04-16 13:11:49 UTC
openSUSE-SU-2019:1213-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
openSUSE Leap 42.3 (src):    SDL-1.2.15-20.3.1
Comment 16 Swamp Workflow Management 2019-04-17 19:24:32 UTC
openSUSE-SU-2019:1223-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
openSUSE Leap 15.0 (src):    SDL-1.2.15-lp150.2.3.1
Comment 17 Swamp Workflow Management 2019-04-23 19:13:29 UTC
openSUSE-SU-2019:1261-1: An update that fixes 11 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099
CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638
Sources used:
openSUSE Leap 15.0 (src):    SDL2-2.0.8-lp150.2.3.1
Comment 18 Marcus Meissner 2019-06-27 10:21:31 UTC
released