ALT-BU-2019-3907-1
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2015-03137
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-09693
Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2010-2891
Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.
- SUSE-SR:2011:001
- SUSE-SR:2011:001
- SUSE-SR:2011:002
- SUSE-SR:2011:002
- 41841
- 41841
- 42877
- 42877
- 42902
- 42902
- 43068
- 43068
- http://security-tracker.debian.org/tracker/CVE-2010-2891
- http://security-tracker.debian.org/tracker/CVE-2010-2891
- http://www.coresecurity.com/content/libsmi-smigetnode-buffer-overflow
- http://www.coresecurity.com/content/libsmi-smigetnode-buffer-overflow
- DSA-2145
- DSA-2145
- 15293
- 15293
- MDVSA-2010:209
- MDVSA-2010:209
- 20101020 [CORE-2010-0819] LibSMI smiGetNode Buffer Overflow When Long OID Is Given In Numerical Form
- 20101020 [CORE-2010-0819] LibSMI smiGetNode Buffer Overflow When Long OID Is Given In Numerical Form
- 44276
- 44276
- ADV-2010-2764
- ADV-2010-2764
- ADV-2011-0076
- ADV-2011-0076
- ADV-2011-0111
- ADV-2011-0111
- ADV-2011-0212
- ADV-2011-0212
- libsmi-smigetnode-bo(62686)
- libsmi-smigetnode-bo(62686)
Closed vulnerabilities
BDU:2019-01623
Уязвимость функции wNumCoef мультимедийной библиотеки SDL, связанная с чтением за границами буфера данных, позволяющая нарушителю получить несанкционированный доступ к информации
BDU:2020-04698
Уязвимость функции IMA_ADPCM_nibble библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04699
Уязвимость функции InitMS_ADPCM библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04700
Уязвимость функции IMA_ADPCM_decode библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04701
Уязвимость функции MS_ADPCM_decode библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04702
Уязвимость функции InitMS_ADPCM библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04703
Уязвимость функции SDL_LoadWAV_RW библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04704
Уязвимость функции InitIMA_ADPCM библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04717
Уязвимость функции Blit1to4 библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04718
Уязвимость функции SDL_GetRGB библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04719
Уязвимость функции SDL_FillRect библиотеки Simple DirectMedia Layer , позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2020-04720
Уязвимость функции Map1toN библиотеки Simple DirectMedia Layer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-03748
Уязвимость функция BlitNtoN (video/SDL_blit_N.c) мультимедийной библиотеки Simple DirectMedia Layer, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании
BDU:2023-02638
Уязвимость функции IMA_ADPCM_decode() компонента audio/SDL_wave.c мультимедийной библиотеки Simple DirectMedia Layer, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-12222
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.
- openSUSE-SU-2019:2070
- openSUSE-SU-2019:2070
- openSUSE-SU-2019:2108
- openSUSE-SU-2019:2108
- https://bugzilla.libsdl.org/show_bug.cgi?id=4621
- https://bugzilla.libsdl.org/show_bug.cgi?id=4621
- [debian-lts-announce] 20190722 [SECURITY] [DLA 1861-1] libsdl2-image security update
- [debian-lts-announce] 20190722 [SECURITY] [DLA 1861-1] libsdl2-image security update
- [debian-lts-announce] 20190727 [SECURITY] [DLA 1865-1] sdl-image1.2 security update
- [debian-lts-announce] 20190727 [SECURITY] [DLA 1865-1] sdl-image1.2 security update
- FEDORA-2020-ff2fe47ba4
- FEDORA-2020-ff2fe47ba4
- FEDORA-2019-a6bc0fb143
- FEDORA-2019-a6bc0fb143
- USN-4238-1
- USN-4238-1
Modified: 2024-11-21
CVE-2019-13616
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
- openSUSE-SU-2019:2070
- openSUSE-SU-2019:2070
- openSUSE-SU-2019:2071
- openSUSE-SU-2019:2071
- openSUSE-SU-2019:2108
- openSUSE-SU-2019:2108
- openSUSE-SU-2019:2109
- openSUSE-SU-2019:2109
- openSUSE-SU-2019:2226
- openSUSE-SU-2019:2226
- openSUSE-SU-2019:2224
- openSUSE-SU-2019:2224
- RHSA-2019:3950
- RHSA-2019:3950
- RHSA-2019:3951
- RHSA-2019:3951
- RHSA-2020:0293
- RHSA-2020:0293
- https://bugzilla.libsdl.org/show_bug.cgi?id=4538
- https://bugzilla.libsdl.org/show_bug.cgi?id=4538
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- FEDORA-2020-24652fe41c
- FEDORA-2020-ff2fe47ba4
- FEDORA-2020-ff2fe47ba4
- FEDORA-2019-e08f78d4a6
- FEDORA-2019-e08f78d4a6
- FEDORA-2019-446ca9f695
- FEDORA-2019-446ca9f695
- FEDORA-2019-8ef33a69ca
- FEDORA-2019-8ef33a69ca
- GLSA-202305-17
- GLSA-202305-17
- USN-4156-1
- USN-4156-1
- USN-4156-2
- USN-4156-2
- USN-4238-1
- USN-4238-1
Modified: 2024-11-21
CVE-2019-13626
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
- openSUSE-SU-2019:2226
- openSUSE-SU-2019:2226
- openSUSE-SU-2019:2224
- openSUSE-SU-2019:2224
- https://bugzilla.libsdl.org/show_bug.cgi?id=4522
- https://bugzilla.libsdl.org/show_bug.cgi?id=4522
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-ff2fe47ba4
- FEDORA-2020-ff2fe47ba4
- GLSA-201909-07
- GLSA-201909-07
Modified: 2024-11-21
CVE-2019-14906
A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface into a new optimized one, due to a lack of validation while loading a BMP image, is possible. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or execute code.
Modified: 2024-11-21
CVE-2019-7572
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4495
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4495
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7573
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4491
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4491
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7574
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4496
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4496
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7575
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4493
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4493
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7576
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4490
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4490
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7577
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4492
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- FEDORA-2019-918aad6bd5
- FEDORA-2019-bf531902c8
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2019-bf531902c8
- FEDORA-2019-918aad6bd5
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4492
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7578
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4494
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4494
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7635
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:2071
- openSUSE-SU-2019:2109
- https://bugzilla.libsdl.org/show_bug.cgi?id=4498
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190722 [SECURITY] [DLA 1861-1] libsdl2-image security update
- [debian-lts-announce] 20190727 [SECURITY] [DLA 1865-1] sdl-image1.2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4143-1
- USN-4156-1
- USN-4156-2
- USN-4238-1
- openSUSE-SU-2019:1213
- USN-4238-1
- USN-4156-2
- USN-4156-1
- USN-4143-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190727 [SECURITY] [DLA 1865-1] sdl-image1.2 security update
- [debian-lts-announce] 20190722 [SECURITY] [DLA 1861-1] libsdl2-image security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4498
- openSUSE-SU-2019:2109
- openSUSE-SU-2019:2071
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7636
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4499
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4143-1
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- USN-4143-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4499
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7637
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1633
- openSUSE-SU-2019:1632
- https://bugzilla.libsdl.org/show_bug.cgi?id=4497
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2803-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- FEDORA-2020-24652fe41c
- USN-4143-1
- USN-4156-1
- USN-4156-2
- openSUSE-SU-2019:1213
- USN-4156-2
- USN-4156-1
- USN-4143-1
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2803-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4497
- openSUSE-SU-2019:1632
- openSUSE-SU-2019:1633
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Modified: 2024-11-21
CVE-2019-7638
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
- openSUSE-SU-2019:1213
- openSUSE-SU-2019:1223
- openSUSE-SU-2019:1261
- https://bugzilla.libsdl.org/show_bug.cgi?id=4500
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- FEDORA-2020-24652fe41c
- GLSA-201909-07
- GLSA-202305-17
- USN-4143-1
- USN-4156-1
- openSUSE-SU-2019:1213
- USN-4156-1
- USN-4143-1
- GLSA-202305-17
- GLSA-201909-07
- FEDORA-2020-24652fe41c
- [debian-lts-announce] 20230208 [SECURITY] [DLA 3314-1] libsdl2 security update
- [debian-lts-announce] 20211031 [SECURITY] [DLA 2804-1] libsdl1.2 security update
- [debian-lts-announce] 20210130 [SECURITY] [DLA 2536-1] libsdl2 security update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1714-2] libsdl2 regression update
- [debian-lts-announce] 20191017 [SECURITY] [DLA 1713-2] libsdl1.2 regression update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1714-1] libsdl2 security update
- [debian-lts-announce] 20190313 [SECURITY] [DLA 1713-1] libsdl1.2 security update
- https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720
- https://bugzilla.libsdl.org/show_bug.cgi?id=4500
- openSUSE-SU-2019:1261
- openSUSE-SU-2019:1223
Closed bugs
Поправить зависимости
Closed bugs
[FR] 1.6
Closed bugs
avrdude: can't open config file "/etc/avrdude/avrdude.conf": No such file or directory
Package kernel-image-std-def updated to version 4.19.69-alt1 for branch sisyphus in task 236812.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-15538
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
- openSUSE-SU-2019:2173
- openSUSE-SU-2019:2173
- openSUSE-SU-2019:2181
- openSUSE-SU-2019:2181
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee
- [debian-lts-announce] 20190914 [SECURITY] [DLA 1919-1] linux-4.9 security update
- [debian-lts-announce] 20190914 [SECURITY] [DLA 1919-1] linux-4.9 security update
- [debian-lts-announce] 20190915 [SECURITY] [DLA 1919-2] linux-4.9 security update
- [debian-lts-announce] 20190915 [SECURITY] [DLA 1919-2] linux-4.9 security update
- FEDORA-2019-97380355ae
- FEDORA-2019-97380355ae
- FEDORA-2019-4c91a2f76e
- FEDORA-2019-4c91a2f76e
- https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
- https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
- https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
- https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
- https://security.netapp.com/advisory/ntap-20191004-0001/
- https://security.netapp.com/advisory/ntap-20191004-0001/
- https://support.f5.com/csp/article/K32592426?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K32592426?utm_source=f5support&%3Butm_medium=RSS
- USN-4144-1
- USN-4144-1
- USN-4147-1
- USN-4147-1
Package kernel-image-un-def updated to version 5.2.11-alt1 for branch sisyphus in task 236820.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-15538
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well in remote DoS if the XFS filesystem is exported for instance via NFS.
- openSUSE-SU-2019:2173
- openSUSE-SU-2019:2173
- openSUSE-SU-2019:2181
- openSUSE-SU-2019:2181
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee
- https://github.com/torvalds/linux/commit/1fb254aa983bf190cfd685d40c64a480a9bafaee
- [debian-lts-announce] 20190914 [SECURITY] [DLA 1919-1] linux-4.9 security update
- [debian-lts-announce] 20190914 [SECURITY] [DLA 1919-1] linux-4.9 security update
- [debian-lts-announce] 20190915 [SECURITY] [DLA 1919-2] linux-4.9 security update
- [debian-lts-announce] 20190915 [SECURITY] [DLA 1919-2] linux-4.9 security update
- FEDORA-2019-97380355ae
- FEDORA-2019-97380355ae
- FEDORA-2019-4c91a2f76e
- FEDORA-2019-4c91a2f76e
- https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
- https://lore.kernel.org/linux-xfs/20190823035528.GH1037422%40magnolia/
- https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
- https://lore.kernel.org/linux-xfs/20190823192433.GA8736%40eldamar.local
- https://security.netapp.com/advisory/ntap-20191004-0001/
- https://security.netapp.com/advisory/ntap-20191004-0001/
- https://support.f5.com/csp/article/K32592426?utm_source=f5support&%3Butm_medium=RSS
- https://support.f5.com/csp/article/K32592426?utm_source=f5support&%3Butm_medium=RSS
- USN-4144-1
- USN-4144-1
- USN-4147-1
- USN-4147-1
Closed bugs
Пакет libirman зависит по сборке сам на себя