Bug 26085

Summary: SDL_image possible new security issues CVE-2019-5051 and CVE-2019-12216
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Nicolas Salguero <nicolas.salguero>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: major    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA7TOO
Source RPM: SDL_image-1.2.12-12.1.mga7.src.rpm CVE:
Status comment:

Description David Walser 2020-01-15 23:09:21 CET
Ubuntu has issued an advisory on January 14:
https://usn.ubuntu.com/4238-1/

These two issues don't appear to have been fixed in our previous update in Bug 25766.

Mageia 7 would also be affected.
David Walser 2020-01-15 23:09:28 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Nicolas Salguero 2020-01-16 09:28:32 CET
When checking the list of patches from Ubuntu, I see no new patch for those issues so those CVEs are likely to be fixed by the patches we already have.
Comment 2 David Walser 2020-01-16 13:34:45 CET
Yeah they may be combined into other patches.  Do our patches actually match theirs (in content and not just name)?
Comment 3 Nicolas Salguero 2020-01-16 14:06:19 CET
Yes I also verified the content and we have the same patches as sdl-image1.2 version 1.2.12-12 from Debian, for which CVE-2019-5051 and CVE-2019-12216 are considered as fixed.
Comment 4 David Walser 2020-01-16 14:08:23 CET
Thanks.

*** This bug has been marked as a duplicate of bug 25766 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED