| Summary: | SDL_image possible new security issues CVE-2019-5051 and CVE-2019-12216 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Nicolas Salguero <nicolas.salguero> |
| Status: | RESOLVED DUPLICATE | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | ||
| Version: | Cauldron | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA7TOO | ||
| Source RPM: | SDL_image-1.2.12-12.1.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2020-01-15 23:09:21 CET
David Walser
2020-01-15 23:09:28 CET
Whiteboard:
(none) =>
MGA7TOO When checking the list of patches from Ubuntu, I see no new patch for those issues so those CVEs are likely to be fixed by the patches we already have. Yeah they may be combined into other patches. Do our patches actually match theirs (in content and not just name)? Yes I also verified the content and we have the same patches as sdl-image1.2 version 1.2.12-12 from Debian, for which CVE-2019-5051 and CVE-2019-12216 are considered as fixed. |