ALAS2-2019-1318


Amazon Linux 2 Security Advisory: ALAS-2019-1318
Advisory Release Date: 2019-10-21 18:01 Pacific
Advisory Updated Date: 2019-10-23 23:24 Pacific
Severity: Important

Issue Overview:

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.(CVE-2019-12222)

A heap-based buffer overflow was discovered in SDL in the SDL_BlitCopy() function, that was called while copying an existing surface into a new optimized one, due to lack of validation while loading a BMP image in the SDL_LoadBMP_RW() function. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or possibly execute code.(CVE-2019-13616)


Affected Packages:

SDL2


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update SDL2 to update your system.

New Packages:
aarch64:
    SDL2-2.0.10-1.amzn2.aarch64
    SDL2-devel-2.0.10-1.amzn2.aarch64
    SDL2-static-2.0.10-1.amzn2.aarch64
    SDL2-debuginfo-2.0.10-1.amzn2.aarch64

i686:
    SDL2-2.0.10-1.amzn2.i686
    SDL2-devel-2.0.10-1.amzn2.i686
    SDL2-static-2.0.10-1.amzn2.i686
    SDL2-debuginfo-2.0.10-1.amzn2.i686

src:
    SDL2-2.0.10-1.amzn2.src

x86_64:
    SDL2-2.0.10-1.amzn2.x86_64
    SDL2-devel-2.0.10-1.amzn2.x86_64
    SDL2-static-2.0.10-1.amzn2.x86_64
    SDL2-debuginfo-2.0.10-1.amzn2.x86_64