Bug 26085 - SDL_image possible new security issues CVE-2019-5051 and CVE-2019-12216
Summary: SDL_image possible new security issues CVE-2019-5051 and CVE-2019-12216
Status: RESOLVED DUPLICATE of bug 25766
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Nicolas Salguero
QA Contact: Sec team
Whiteboard: MGA7TOO
Depends on:
Reported: 2020-01-15 23:09 CET by David Walser
Modified: 2020-01-16 14:08 CET (History)
0 users

See Also:
Source RPM: SDL_image-1.2.12-12.1.mga7.src.rpm
Status comment:


Description David Walser 2020-01-15 23:09:21 CET
Ubuntu has issued an advisory on January 14:

These two issues don't appear to have been fixed in our previous update in Bug 25766.

Mageia 7 would also be affected.
David Walser 2020-01-15 23:09:28 CET

Whiteboard: (none) => MGA7TOO

Comment 1 Nicolas Salguero 2020-01-16 09:28:32 CET
When checking the list of patches from Ubuntu, I see no new patch for those issues so those CVEs are likely to be fixed by the patches we already have.
Comment 2 David Walser 2020-01-16 13:34:45 CET
Yeah they may be combined into other patches.  Do our patches actually match theirs (in content and not just name)?
Comment 3 Nicolas Salguero 2020-01-16 14:06:19 CET
Yes I also verified the content and we have the same patches as sdl-image1.2 version 1.2.12-12 from Debian, for which CVE-2019-5051 and CVE-2019-12216 are considered as fixed.
Comment 4 David Walser 2020-01-16 14:08:23 CET

*** This bug has been marked as a duplicate of bug 25766 ***

Resolution: (none) => DUPLICATE

Note You need to log in before you can comment on or make changes to this bug.