Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (2)
Triage CVE-2018-3977 (libsdl2-image, sdl-image1.2) for stretch as per private correspondence w/jmm)
· bb671421
Chris Lamb
authored
Nov 07, 2018
bb671421
Triage CVE-2018-3977 (libsdl2-image, sdl-image1.2) for jessie LTS.
· f65b1d84
Chris Lamb
authored
Nov 07, 2018
f65b1d84
Hide whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
f65b1d84
...
...
@@ -40248,6 +40248,10 @@ CVE-2018-3978 (An exploitable out-of-bounds write vulnerability exists in the Wo
CVE-2018-3977 (An exploitable code execution vulnerability exists in the XCF image ...)
- libsdl2-image 2.0.3+dfsg1-3 (bug #912617)
- sdl-image1.2 1.2.12-10 (bug #912618)
[stretch] - libsdl2-image <no-dsa> (Minor issue)
[jessie] - libsdl2-image <no-dsa> (Minor issue)
[stretch] - sdl-image1.2 <no-dsa> (Minor issue)
[jessie] - sdl-image1.2 <no-dsa> (Minor issue)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2018-0645
NOTE: https://hg.libsdl.org/SDL_image/rev/170d7d32e4a8
CVE-2018-3976
data/dla-needed.txt
View file @
f65b1d84
...
...
@@ -50,8 +50,6 @@ liblivemedia (Hugo Lefeuvre)
NOTE: CVE entry says remote: "no", but it looks like a pretty exploitable remote vulnerability
NOTE: (remote code execution)... CVE is very well documented so I think this is worth a patch
--
libsdl2-image (Chris Lamb)
--
linux (Ben Hutchings)
--
linux-4.9 (Ben Hutchings)
...
...
@@ -77,8 +75,6 @@ qemu (Santiago)
--
salt (Mike Gabriel)
--
sdl-image1.2 (Chris Lamb)
--
spamassassin (Antoine Beaupre)
--
squid3 (Abhijith PA)
...
...