Your message dated Sat, 31 Aug 2019 23:17:34 +0000
with message-id <[email protected]>
and subject line Bug#932755: fixed in sdl-image1.2 1.2.12-5+deb9u2
has caused the Debian Bug report #932755,
regarding sdl-image1.2: multiple security issues
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
932755: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=932755
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: sdl-image1.2
Version: 1.2.12-10
Severity: important
Tags: security upstream

Hi,

the following security issues[0] were published for sdl-image1.2:

* CVE-2019-5052: integer overflow and subsequent buffer overflow in IMG_pcx.c.

* CVE-2019-5051: heap-based buffer overflow in IMG_pcx.c.

* CVE-2019-7635: heap buffer overflow in Blit1to4 (IMG_bmp.c).

* CVE-2019-12216, CVE-2019-12217,
  CVE-2019-12218, CVE-2019-12219,
  CVE-2019-12220, CVE-2019-12221,
  CVE-2019-12222: OOB R/W in IMG_LoadPCX_RW (IMG_pcx.c).

Fixing these issues:

Patches are quite straightforward and I believe that some of these
issues are worth fixing (reporter claims that they are "exploitable").

I have prepared and uploaded a jessie LTS update addressing most of these
issues (all of them apart from CVE-2019-5051) via targeted fixes.

If the security team agrees, I will provide targeted fixes for buster and
stretch.

For testing, I suggest to package the latest upstream release. If needed, I
can provide an update with targeted fixes.

regards,
Hugo

[0] https://security-tracker.debian.org/tracker/source-package/sdl-image1.2

-- 
                Hugo Lefeuvre (hle)    |    www.owl.eu.com
RSA4096_ 360B 03B3 BF27 4F4D 7A3F D5E8 14AA 1EB8 A247 3DFD
ed25519_ 37B2 6D38 0B25 B8A2 6B9F 3A65 A36F 5357 5F2D DC4C

Attachment: signature.asc
Description: PGP signature


--- End Message ---
--- Begin Message ---
Source: sdl-image1.2
Source-Version: 1.2.12-5+deb9u2

We believe that the bug you reported is fixed in the latest version of
sdl-image1.2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Hugo Lefeuvre <[email protected]> (supplier of updated sdl-image1.2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 29 Aug 2019 08:28:17 -0400
Source: sdl-image1.2
Binary: libsdl-image1.2 libsdl-image1.2-dbg libsdl-image1.2-dev
Architecture: source amd64
Version: 1.2.12-5+deb9u2
Distribution: stretch
Urgency: medium
Maintainer: Debian SDL packages maintainers 
<[email protected]>
Changed-By: Hugo Lefeuvre <[email protected]>
Description:
 libsdl-image1.2 - Image loading library for Simple DirectMedia Layer 1.2, 
libraries
 libsdl-image1.2-dbg - Image loading library for Simple DirectMedia Layer 1.2, 
debugging
 libsdl-image1.2-dev - Image loading library for Simple DirectMedia Layer 1.2, 
developme
Closes: 932755
Changes:
 sdl-image1.2 (1.2.12-5+deb9u2) stretch; urgency=medium
 .
   * Non-maintainer upload.
   * CVE-2018-3977, CVE-2019-5058: buffer overflow in do_layer_surface
     (IMG_xcf.c) (Closes: #932755).
   * CVE-2019-5052: integer overflow and subsequent buffer overflow in 
IMG_pcx.c.
   * CVE-2019-7635: heap buffer overflow in Blit1to4 (IMG_bmp.c).
   * CVE-2019-12216, CVE-2019-12217,
     CVE-2019-12218, CVE-2019-12219,
     CVE-2019-12220, CVE-2019-12221,
     CVE-2019-12222, CVE-2019-5051: OOB R/W in IMG_LoadPCX_RW (IMG_pcx.c).
Checksums-Sha1:
 aac3a0677fa26bb78d16ff551246f2c7adf7b217 2167 sdl-image1.2_1.2.12-5+deb9u2.dsc
 ebe6b94f40e9d3e9616af21d50bc1766fe848e0a 12084 
sdl-image1.2_1.2.12-5+deb9u2.debian.tar.xz
 f29a179dfe56e6e93e363053df6792d921dfb8fa 75690 
libsdl-image1.2-dbg_1.2.12-5+deb9u2_amd64.deb
 1f02958ea8c870171cfeb9a703d205f1cafcb282 39986 
libsdl-image1.2-dev_1.2.12-5+deb9u2_amd64.deb
 62d12211217554b84311d7629f56b283a9f45817 35496 
libsdl-image1.2_1.2.12-5+deb9u2_amd64.deb
 9eabc740599a5304d2e82ea1ceab1eecc7aec26f 10178 
sdl-image1.2_1.2.12-5+deb9u2_amd64.buildinfo
Checksums-Sha256:
 6d259da8b8b622e178aa95ea60c476acc7475d5956614a2f0bde3865c1bf068f 2167 
sdl-image1.2_1.2.12-5+deb9u2.dsc
 a329b684ec2b4d5a2269e6c17efb1b770810451bed245e85ce24d863e888ed98 12084 
sdl-image1.2_1.2.12-5+deb9u2.debian.tar.xz
 c2c60e7d913d374e3419ae5eeee7def04739d470c2d213c3a2ae0dc3c1882513 75690 
libsdl-image1.2-dbg_1.2.12-5+deb9u2_amd64.deb
 ab8471b96579aeccb82f71224c27f3ba8b7a923b31d83d78dae908720eb0dc9b 39986 
libsdl-image1.2-dev_1.2.12-5+deb9u2_amd64.deb
 c66a61bdf073ef3af64b1c2b1740bef613c4a2b632fdf9d297be9946eafda83e 35496 
libsdl-image1.2_1.2.12-5+deb9u2_amd64.deb
 aa5a5dbb25665e4633b5d18447a7f2bbf3f96f5d2b09310549ceab7ea38e2ebe 10178 
sdl-image1.2_1.2.12-5+deb9u2_amd64.buildinfo
Files:
 9e2f25cf74295eba501bf8dcc77ec349 2167 libs optional 
sdl-image1.2_1.2.12-5+deb9u2.dsc
 c59a558c4e4df3aa6ec7f0ff054628bb 12084 libs optional 
sdl-image1.2_1.2.12-5+deb9u2.debian.tar.xz
 1f1b50aa62d03e2980b546ebce6c47dc 75690 debug extra 
libsdl-image1.2-dbg_1.2.12-5+deb9u2_amd64.deb
 a4eaca98f0e69033d15c4bdef5c1c178 39986 libdevel optional 
libsdl-image1.2-dev_1.2.12-5+deb9u2_amd64.deb
 3140e9ec7826d005f2a0c512fe72786f 35496 libs optional 
libsdl-image1.2_1.2.12-5+deb9u2_amd64.deb
 c1f42710d8614df3d845333772d158f3 10178 libs optional 
sdl-image1.2_1.2.12-5+deb9u2_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEeDb9QWtkMa2LX4zREeMFjl5EGkIFAl1n1+IACgkQEeMFjl5E
GkI41wv+KY8CaFMGBvUIqr1t8TEwT6K1WgLhAtmSubQbmvEw/hKo70//E2M6Q/x8
kzkKe4a81EnpwNnQykpz+Q1wGNkf+zoeIH8+dF3LSYLSXnDwRWnF/acq012JQvd8
MQjQsvQTxZwHwQqGyFWnsIZwAsP0WiQUUznUoJ0Yj+ipcP7Tg+QGZBF2HMCTmIZB
5CCvAJQ/WyyLeLiZ8hRIy/qo683FPHWpVejURKv3bx4cbhOUS2Lgs7EVLg1vMzqn
0so5BHf0ZqiAZ+8S6sY+DAdLw+8jxAztAs8eI6c3k9tsWiBzfzPkrUzvjs9e1c+V
uI3wFVsOGOr2+C2xCphumHW3NePdxZtZVuuRECoqlFe6Z6kmIzHbEwz7BuSvibsT
mPSxDb2oR7fe0T/AOowqvH0ZBazru0zU2eYTuC8EPLeUpNy0gV7qCUbzqiKAmtlg
Krt7CHuAEVsYY7N29C+s/Qy9QCzc9lbIVEBllXESvpEQMKsStUVuvf0IZsoacKj0
H98PU2oR
=ACg9
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to