Bugzilla – Bug 1124827
VUL-1: CVE-2019-7635: SDL,SDL2: heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c
Last modified: 2022-03-01 16:17:07 UTC
CVE-2019-7635 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-7635 https://bugzilla.libsdl.org/show_bug.cgi?id=4498 https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
Again all codestream seem affected: - SUSE:SLE-10-SP3:Update - SUSE:SLE-11:Update - SUSE:SLE-12:Update - SUSE:SLE-15:Update For SLE-15 both SDL and SDL2 two upstream fixes: https://bugzilla.libsdl.org/attachment.cgi?id=3645&action=diff https://bugzilla.libsdl.org/attachment.cgi?id=3637&action=diff
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2019-04-09. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/64242
SUSE-SU-2019:13998-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): SDL-1.2.13-106.11.1 SUSE Linux Enterprise Server 11-SP4 (src): SDL-1.2.13-106.11.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): SDL-1.2.13-106.11.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): SDL-1.2.13-106.11.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:0899-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP4 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Server 12-SP4 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Server 12-SP3 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Desktop 12-SP4 (src): SDL-1.2.15-15.11.1 SUSE Linux Enterprise Desktop 12-SP3 (src): SDL-1.2.15-15.11.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:0917-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15 (src): SDL-1.2.15-3.9.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:0950-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: SUSE Linux Enterprise Module for Desktop Applications 15 (src): SDL2-2.0.8-3.9.1 *** NOTE: This information is not intended to be used for external communication, because this may only be a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:1223-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: openSUSE Leap 15.0 (src): SDL-1.2.15-lp150.2.3.1
openSUSE-SU-2019:1261-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: openSUSE Leap 15.0 (src): SDL2-2.0.8-lp150.2.3.1
openSUSE-SU-2019:1213-1: An update that fixes 11 vulnerabilities is now available. Category: security (moderate) Bug References: 1124799,1124800,1124802,1124803,1124805,1124806,1124824,1124825,1124826,1124827,1125099 CVE References: CVE-2019-7572,CVE-2019-7573,CVE-2019-7574,CVE-2019-7575,CVE-2019-7576,CVE-2019-7577,CVE-2019-7578,CVE-2019-7635,CVE-2019-7636,CVE-2019-7637,CVE-2019-7638 Sources used: openSUSE Leap 42.3 (src): SDL-1.2.15-20.3.1
releaed
openSUSE-SU-2019:2071-1: An update that fixes 7 vulnerabilities is now available. Category: security (moderate) Bug References: 1124827,1140421,1141844,1143763,1143764,1143766,1143768 CVE References: CVE-2019-13616,CVE-2019-5052,CVE-2019-5057,CVE-2019-5058,CVE-2019-5059,CVE-2019-5060,CVE-2019-7635 Sources used: openSUSE Leap 15.1 (src): SDL_image-1.2.12+hg695-lp151.3.3.1 openSUSE Leap 15.0 (src): SDL_image-1.2.12+hg695-lp150.2.3.1
openSUSE-SU-2019:2109-1: An update that fixes 7 vulnerabilities is now available. Category: security (moderate) Bug References: 1124827,1140421,1141844,1143763,1143764,1143766,1143768 CVE References: CVE-2019-13616,CVE-2019-5052,CVE-2019-5057,CVE-2019-5058,CVE-2019-5059,CVE-2019-5060,CVE-2019-7635 Sources used: openSUSE Backports SLE-15-SP1 (src): SDL_image-1.2.12+hg695-bp151.4.3.1 openSUSE Backports SLE-15 (src): SDL_image-1.2.12+hg695-bp150.3.3.1