==========================================================================
Ubuntu Security Notice USN-4156-1
October 15, 2019
libsdl1.2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in SDL.
Software Description:
– libsdl1.2: Simple DirectMedia Layer
Details:
It was discovered that SDL incorrectly handled certain images. If a user
were tricked into opening a crafted image file, a remote attacker could
use this issue to cause SDL to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
  libsdl1.2debian                 1.2.15+dfsg2-0.1ubuntu0.1
Ubuntu 16.04 LTS:
  libsdl1.2debian                 1.2.15+dfsg1-3ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
  https://usn.ubuntu.com/4156-1
  CVE-2019-13616, CVE-2019-7572, CVE-2019-7573, CVE-2019-7574,
  CVE-2019-7575, CVE-2019-7576, CVE-2019-7577, CVE-2019-7578,
  CVE-2019-7635, CVE-2019-7636, CVE-2019-7637, CVE-2019-7638
Package Information:
  https://launchpad.net/ubuntu/+source/libsdl1.2/1.2.15+dfsg2-0.1ubuntu0.1
  https://launchpad.net/ubuntu/+source/libsdl1.2/1.2.15+dfsg1-3ubuntu0.1
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl2mED8ACgkQZWnYVadE
vpN8GA/+Ju91Z2ZHUyfUyz2Sjnew+pVBA/VDrlglWe890C2+K3oZCisbWkF0atVm
cB7Ttbp0zL8kNmdzowXBRjfgkrTeff0SOcysh0APqNSCuLg1Y12W4qofVZUs9YeP
W+gW4aKie6sdOZo5J0q2TL0zB9ZsiYZ+o/ZfhpWKi+3C72VtHjOSaDsGtIKkeO6D
ynF/93WixGo5/pqjxVkecPYlS7RCzhusbTbks3l1qHU3HIt0Iib7DimozNHSol/G
YLm8gxp4HJhBFSbIWioxEDbXvXqyGdJadRdsNGJ2mSJQI+mmJtANsHLCDPnTzobE
pBpVPa9nZAr9HaF2/MY4dXZMP4ncp95fX4lW+kumKj3ibCcwI7WWMPAFisQ2Gi9w
BfKlV6y7yFjI2ipCxJz81jtzeBMPtBGVmIlKcdR6JEW0YNHT7pVoJYrOFbbQeeDi
HDtCsu2KDJOTK5SV+0Qpd0hGvOLWVq+urGwX8ODUClasbclNdGwyZP4tkOMqkOmt
XQu2jX856WxqIu/tCyYbuGfWcGddsKZGeU+ohsUa2nU719JdybYvNq8jirG0kM6y
xzmaLhW9SWQ3CLIVXWHxaevX3No2Gf1LfoiHYBh9HSUM2nQX2z8CjN51Qiwy7Fno
fpedUR3gS/GQacaAWb+MXMcZyZAt/EuSyV6DESZPaNnQko2Sp+M=
=1Wpi
—–END PGP SIGNATURE—–
—



