Amazon Linux 2 Security Advisory: ALAS-2019-1318
Advisory Release Date: 2019-10-21 18:01 Pacific
Advisory Updated Date: 2019-10-23 23:24 Pacific
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.(CVE-2019-12222)
A heap-based buffer overflow was discovered in SDL in the SDL_BlitCopy() function, that was called while copying an existing surface into a new optimized one, due to lack of validation while loading a BMP image in the SDL_LoadBMP_RW() function. An application that uses SDL to parse untrusted input files may be vulnerable to this flaw, which could allow an attacker to make the application crash or possibly execute code.(CVE-2019-13616)
Affected Packages:
SDL2
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update SDL2 to update your system.
aarch64:
SDL2-2.0.10-1.amzn2.aarch64
SDL2-devel-2.0.10-1.amzn2.aarch64
SDL2-static-2.0.10-1.amzn2.aarch64
SDL2-debuginfo-2.0.10-1.amzn2.aarch64
i686:
SDL2-2.0.10-1.amzn2.i686
SDL2-devel-2.0.10-1.amzn2.i686
SDL2-static-2.0.10-1.amzn2.i686
SDL2-debuginfo-2.0.10-1.amzn2.i686
src:
SDL2-2.0.10-1.amzn2.src
x86_64:
SDL2-2.0.10-1.amzn2.x86_64
SDL2-devel-2.0.10-1.amzn2.x86_64
SDL2-static-2.0.10-1.amzn2.x86_64
SDL2-debuginfo-2.0.10-1.amzn2.x86_64