OESA-2021-1426
Dashboard / Vulnerabilities / OESA-2021-1426
OESA-2021-1426
Summary: SDL security update
Details: Simple DirectMedia Layer(SDL) is a cross-platform development library designed\ to provide low level access to audio, keyboard, mouse, joystick, and graphics\ hardware via OpenGL and Direct3D. It is used by video playback software, emulators,\ and popular games including Valve's award winning catalog and many Humble Bundle games.\ Security Fix(es): SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.(CVE-2019-7572) SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7574) SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.(CVE-2019-7575)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1426, https://nvd.nist.gov/vuln/detail/CVE-2019-7572, https://nvd.nist.gov/vuln/detail/CVE-2019-7574, https://nvd.nist.gov/vuln/detail/CVE-2019-7575
Affected packages
Package
Name: SDL
Purl: pkg:rpm/openEuler/SDL&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
