ALINUX2-SA-2020%3A0123
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-7572: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c. CVE-2019-7573: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop). CVE-2019-7574: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c. CVE-2019-7575: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c. CVE-2019-7576: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop). CVE-2019-7577: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c. CVE-2019-7578: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c. CVE-2019-7635: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c. CVE-2019-7636: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c. CVE-2019-7637: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c. CVE-2019-7638: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | SDL |
Timeline
- Oct 9, 2020 CVE Updated
- Oct 10, 2020 CVE Published
References
- ALINUX2-SA-2020:0123: SDL security update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7572 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7573 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7574 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7575 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7576 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7577 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7578 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7635 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7636 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7637 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7638 advisory