Advisories ยป MGASA-2017-0398

Updated sdl2 packages fix security vulnerability

Publication date: 02 Nov 2017
Modification date: 02 Nov 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-2888

Description

Yves Younan of Cisco Talos discovered an exploitable integer overflow
vulnerability when creating a new RGB Surface in SDL 2.0.x before
version 2.0.7. A specially crafted file can cause an integer overflow
resulting in too little memory being allocated which can lead to a
buffer overflow and potential code execution. An attacker can provide a
specially crafted image file to trigger this vulnerability
(CVE-2017-2888).
                

References

SRPMS

5/core

6/core