• [gentoo-announce] [ GLSA 202305-18 ] libsdl2: Multiple Vulnerabilities

    From glsamaker@gentoo.org@21:1/5 to All on Wed May 3 12:30:02 2023
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202305-18
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
    Title: libsdl2: Multiple Vulnerabilities
    Date: May 03, 2023
    Bugs: #836665, #890614
    ID: 202305-18

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been found in libsdl2, the worst of which
    could result in arbitrary code execution.

    Background
    ==========

    Simple DirectMedia Layer is a cross-platform development library
    designed to provide low level access to audio, keyboard, mouse,
    joystick, and graphics hardware via OpenGL and Direct3D.

    Affected packages
    =================

    -------------------------------------------------------------------
    Package / Vulnerable / Unaffected
    -------------------------------------------------------------------
    1 media-libs/libsdl2 < 2.26.0 >= 2.26.0

    Description
    ===========

    Multiple vulnerabilities have been discovered in libsdl2. Please review
    the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All libsdl2 users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=media-libs/libsdl2-2.26.0"

    References
    ==========

    [ 1 ] CVE-2021-33657
    https://nvd.nist.gov/vuln/detail/CVE-2021-33657
    [ 2 ] CVE-2022-4743
    https://nvd.nist.gov/vuln/detail/CVE-2022-4743

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202305-18

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2023 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmRSMawACgkQFMQkOaVy +9mJnA//Z0S0VsCWekTO9Pj0XgwfttB6BtP6qvWaT6AQ2U65DG3I4lZ6AYL42DNv ehW57dcR832SycoM6tCmSKvIkNzH3sOARtNSUZjxesDzX3hEmD48Sx09qmIa8UFm wylSa6ycnku4lDm6BWFXSWYeOm4Sh9ukfAgUG+VN8RCLkQ5ZeMb+w9AllaTSz8e0 AooeVmUNkhPwVGNR6rsRRNHx72R33Xfk8qvHdtRpI9vzGruuulQFG7gw6Q08WxiF Gw5o5KY8Rz15T9aCyedzPSXztEJfosheLC9h0FTXFptirj78Nmt3XrO2G6JGeAXv 2AvukfKf/+K5Tk+M8QiQdLSw8xMwg6bnLYGawoPvvEiRIHL62fLt4N1SrPUev+4B uZX7YcjtdLLhCtQXRu662DwREgugvWUR7bONymip0e5wbjLMivBkt5ut7girdyjo DNRId8M2VqGmMD4u4C2pUb8T0m4nDePPPkDUPbjM17V3sp2OC1PZA9j3ADz9rBQV /8JYgnX4M0+LxNJIaK28zhRfXN+1R4e1O4UtgNtAb2UHHVEIe+p249KdQxgP5Mrq PrhVs97gtzntA+Ey1B9M1t6ucoQHB7zodavmYDwKerZ9/lu5TRtCl1MBwD8ndWVK YNhPy2eSP7vWsPYiBnLKRphr9cOoT68JfwgsqSVyKduttrlrRzU=
    =gDV3
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)