MGASA-2022-0326
Dashboard / Vulnerabilities / MGASA-2022-0326
Summary: Updated sdl2 packages fix security vulnerability
Details: There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, for denial of service, or for Code execution. (CVE-2021-33657)
References: https://advisories.mageia.org/MGASA-2022-0326.html, https://bugs.mageia.org/show_bug.cgi?id=30293, https://lists.suse.com/pipermail/sle-security-updates/2022-April/010735.html, https://lists.opensuse.org/archives/list/[email protected]/thread/RT4PK6MXMUBIFIGD2YA7HAH4DD43QU3Z/, https://ubuntu.com/security/notices/USN-5398-1
Affected packages
Package
Name: sdl2
Purl: pkg:rpm/mageia/sdl2?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
