Bug 10103

Summary: CVE-2019-13616 in SDL12 and SDL_image packages
Product: [ROSA-based products] ROSA Fresh Reporter: Andrey Bondrov <andrey.bondrov>
Component: Packages from MainAssignee: ROSA Linux Bugs <bugs>
Status: VERIFIED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: alzim, v.potapov, zombie.ryushu
Version: AllFlags: v.potapov: qa_verified+
alzim: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Platform: --- ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Andrey Bondrov 2019-08-31 04:56:05 MSK
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.

SDL_image is also affected.
Comment 1 Andrey Bondrov 2019-08-31 05:00:32 MSK
Advisory: "Fix CVE-2019-7572, CVE-2019-7573, CVE-2019-7574, CVE-2019-7575, CVE-2019-7576, CVE-2019-7577, CVE-2019-7578, CVE-2019-7635, CVE-2019-7636, CVE-2019-7637, CVE-2019-7638 and CVE-2019-13616 in SDL12"

https://abf.rosalinux.ru/build_lists/3092739
https://abf.rosalinux.ru/build_lists/3092740

Advisory: "Fix CVE-2019-13616 in SDL_image"

https://abf.rosalinux.ru/build_lists/3092732
https://abf.rosalinux.ru/build_lists/3092733
Comment 2 Vladimir Potapov 2019-09-06 16:43:06 MSK
The update is sent to expanded testing
****************************************
Comment 3 Алзим 2019-09-08 21:23:12 MSK
*** Bug 7277 has been marked as a duplicate of this bug. ***
Comment 4 Vladimir Potapov 2019-09-09 17:31:16 MSK
SDL12-1.2.15-15
https://abf.rosalinux.ru/build_lists/3092739
https://abf.rosalinux.ru/build_lists/3092740

SDL_image-1.2.12-12
https://abf.rosalinux.ru/build_lists/3092732
https://abf.rosalinux.ru/build_lists/3092733
******************************* Advisory **************************
Fix CVE-2019-7572, CVE-2019-7573, CVE-2019-7574, CVE-2019-7575, CVE-2019-7576, CVE-2019-7577, CVE-2019-7578, CVE-2019-7635, CVE-2019-7636, CVE-2019-7637, CVE-2019-7638 and CVE-2019-13616 in SDL12.
Fix CVE-2019-13616 in SDL_image.
*******************************************************************
QA Verified