Bugzilla – Bug 1125099
VUL-1: CVE-2019-7578: SDL,SDL2: heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c
Last modified: 2022-03-01 16:17:11 UTC
CVE-2019-7578 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-7578 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-7578.html https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720 https://bugzilla.libsdl.org/show_bug.cgi?id=4494
upstream patch: https://bugzilla.libsdl.org/attachment.cgi?id=3623&action=diff
All codestreams affected: - SUSE:SLE-10-SP3:Update - SUSE:SLE-11:Update - SUSE:SLE-12:Update - SUSE:SLE-15:Update SDL and SDL2 for SLE15
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2019-04-09. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/64242
SUSE-SU-2019:13998-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): SDL-1.2.13-106.11.1 SUSE Linux Enterprise Server 11-SP4 (src): SDL-1.2.13-106.11.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): SDL-1.2.13-106.11.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): SDL-1.2.13-106.11.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:0899-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Server 12-SP4 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Server 12-SP3 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Desktop 12-SP4 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Desktop 12-SP3 (src): SDL-1.2.15-15.11.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:0917-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15 (src): SDL-1.2.15-3.9.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:0950-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15 (src): SDL2-2.0.8-3.9.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:1223-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: openSUSE Leap 15.0 (src): SDL-1.2.15-lp150.2.3.1
openSUSE-SU-2019:1261-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: openSUSE Leap 15.0 (src): SDL2-2.0.8-lp150.2.3.1
openSUSE-SU-2019:1213-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: openSUSE Leap 42.3 (src): SDL-1.2.15-20.3.1
released