Overview

Request 585027 revoked

- Update to new upstream release 2.0.3
* Fixed a number of security issues:
* TALOS-2017-0488/CVE-2017-12122/boo#1084256:
IMG_LoadLBM_RW code execution vulnerability
* TALOS-2017-0489/CVE-2017-14440/boo#1084257:
ILBM CMAP parsing code execution vulnerability
* TALOS-2017-0490/CVE-2017-14441/boo#1084282:
ICO pitch handling code execution vulnerability
* TALOS-2017-0491/CVE-2017-14442/boo#1084304:
Image palette population code execution vulnerability
* TALOS-2017-0497/CVE-2017-14448/boo#1084303:
load_xcf_tile_rle decompression code execution
* TALOS-2017-0498/CVE-2017-14449/boo#1084297:
do_layer_surface double free vulnerability
* TALOS-2017-0499/CVE-2017-14450/boo#1084288:
LWZ decompression buffer overflow vulnerability

Request History
Andreas Stieger's avatar

AndreasStieger created request

- Update to new upstream release 2.0.3
* Fixed a number of security issues:
* TALOS-2017-0488/CVE-2017-12122/boo#1084256:
IMG_LoadLBM_RW code execution vulnerability
* TALOS-2017-0489/CVE-2017-14440/boo#1084257:
ILBM CMAP parsing code execution vulnerability
* TALOS-2017-0490/CVE-2017-14441/boo#1084282:
ICO pitch handling code execution vulnerability
* TALOS-2017-0491/CVE-2017-14442/boo#1084304:
Image palette population code execution vulnerability
* TALOS-2017-0497/CVE-2017-14448/boo#1084303:
load_xcf_tile_rle decompression code execution
* TALOS-2017-0498/CVE-2017-14449/boo#1084297:
do_layer_surface double free vulnerability
* TALOS-2017-0499/CVE-2017-14450/boo#1084288:
LWZ decompression buffer overflow vulnerability


Saul Goodman's avatar

licensedigger accepted review

ok


Maintenance Bot's avatar

maintbot added SDL2_image as a reviewer

Submission for SDL2_image by someone who is not maintainer in the devel project (games). Please review


Maintenance Bot's avatar

maintbot added SDL2 as a reviewer

Submission for SDL2 by someone who is not maintainer in the devel project (games). Please review


Maintenance Bot's avatar

maintbot accepted review

ok


Andreas Stieger's avatar

AndreasStieger revoked request

build experiment

openSUSE Build Service is sponsored by