MGASA-2017-0397
Dashboard / Vulnerabilities / MGASA-2017-0397
Summary: Updated sdl2_image & mingw packages fix security vulnerability
Details: An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a specially crafted XCF file to trigger this vulnerability (CVE-2017-2887).
References: https://advisories.mageia.org/MGASA-2017-0397.html, https://bugs.mageia.org/show_bug.cgi?id=21881, https://lists.fedoraproject.org/archives/list/[email protected]/thread/C7QAEI2QV3QGJR5OS43R5U3U47LAHQRO/
Affected packages
Package
Name: sdl2_image
Purl: pkg:rpm/mageia/sdl2_image?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
