Advisories ยป MGASA-2022-0332

Updated SDL12 packages fix security vulnerability

Publication date: 16 Sep 2022
Modification date: 16 Sep 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-33657 , CVE-2022-34568

Description

There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple
DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP
file, an attacker can cause the application using this library to crash,
denial of service or Code execution. (CVE-2021-33657)

SDL v1.2 was discovered to contain a use-after-free via the XFree function
at /src/video/x11/SDL_x11yuv.c. (CVE-2022-34568)
                

References

SRPMS

8/core