File _patchinfo of Package patchinfo.7397
<patchinfo incident="7397"> <issue id="2017-2888" tracker="cve" /> <issue id="1062784" tracker="bnc">VUL-0: CVE-2017-2888: SDL: Incorrect XCF property handling</issue> <category>security</category> <rating>moderate</rating> <packager>sreeves1</packager> <description>This update for SDL2 fixes the following issues: - CVE-2017-2888: An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability. (bsc#1062784) </description> <summary>Security update for SDL2</summary> </patchinfo>