Debian Package Tracker
Register | Log in
Subscribe

libsdl2-image

Choose email to subscribe with

general
  • source: libsdl2-image (main)
  • version: 2.0.5+dfsg1-3
  • maintainer: Debian SDL packages maintainers (archive) (DMD)
  • uploaders: Felix Geyer [DMD] – Manuel A. Fernandez Montecelo [DMD]
  • arch: any
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.0.1+dfsg-2+deb9u2
  • o-o-sec: 2.0.1+dfsg-2+deb9u1
  • oldstable: 2.0.4+dfsg1-1+deb10u1
  • stable: 2.0.5+dfsg1-2
  • testing: 2.0.5+dfsg1-3
  • unstable: 2.0.5+dfsg1-3
  • exp: 2.5.0~git20220517.gcec4127+dfsg-1
versioned links
  • 2.0.1+dfsg-2+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.1+dfsg-2+deb9u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.4+dfsg1-1+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.5+dfsg1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.5+dfsg1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.5.0~git20220517.gcec4127+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libsdl2-image-2.0-0
  • libsdl2-image-dev
action needed
3 low-priority security issues in buster low

There are 3 open security issues in buster.

3 issues left for the package maintainer to handle:
  • CVE-2019-5059: (needs triaging) An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
  • CVE-2019-5060: (needs triaging) An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
  • CVE-2019-13616: (needs triaging) SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-02-19 Last update: 2022-03-26 14:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.1 instead of 4.6.0).
Created: 2022-05-11 Last update: 2022-05-11 23:24
news
[rss feed]
  • [2022-05-19] Accepted libsdl2-image 2.5.0~git20220517.gcec4127+dfsg-1 (source) into experimental (Simon McVittie)
  • [2022-05-16] Accepted libsdl2-image 2.5.0~git20220516.g99e0e81+dfsg-1-1 (source) into experimental (Simon McVittie)
  • [2022-05-12] Accepted libsdl2-image 2.5.0~git20220512.g686ad26+dfsg-1 (source) into experimental (Simon McVittie)
  • [2022-05-09] Accepted libsdl2-image 2.5.0~git20220508.g406fd40+dfsg-1 (source) into experimental (Simon McVittie)
  • [2022-04-20] Accepted libsdl2-image 2.0.6~20220415.g915b794+dfsg-1 (source) into experimental (Simon McVittie)
  • [2022-03-02] Accepted libsdl2-image 2.0.6~20220301.g3c8c09d3+dfsg-1 (source) into experimental (Simon McVittie)
  • [2022-01-07] Accepted libsdl2-image 2.0.6~20220107.g656ef58+dfsg-1 (source) into experimental (Simon McVittie)
  • [2021-12-14] Accepted libsdl2-image 2.0.6~20211214.g704e516+dfsg-1 (source) into experimental (Simon McVittie)
  • [2021-11-03] libsdl2-image 2.0.5+dfsg1-3 MIGRATED to testing (Debian testing watch)
  • [2021-10-28] Accepted libsdl2-image 2.0.5+dfsg1-3 (source) into unstable (Simon McVittie)
  • [2020-02-09] libsdl2-image 2.0.5+dfsg1-2 MIGRATED to testing (Debian testing watch)
  • [2020-02-03] Accepted libsdl2-image 2.0.5+dfsg1-2 (source) into unstable (Felix Geyer)
  • [2019-08-21] Accepted libsdl2-image 2.0.4+dfsg1-1+deb10u1 (source amd64) into proposed-updates->stable-new, proposed-updates (Hugo Lefeuvre)
  • [2019-07-30] Accepted libsdl2-image 2.0.1+dfsg-2+deb9u2 (source amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Hugo Lefeuvre)
  • [2019-07-29] libsdl2-image 2.0.5+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2019-07-23] Accepted libsdl2-image 2.0.5+dfsg1-1 (source) into unstable (Felix Geyer)
  • [2019-07-22] Accepted libsdl2-image 2.0.0+dfsg-3+deb8u2 (source amd64) into oldoldstable (Hugo Lefeuvre)
  • [2019-02-08] libsdl2-image 2.0.4+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-03] Accepted libsdl2-image 2.0.4+dfsg1-1 (source) into unstable (Felix Geyer)
  • [2018-11-07] libsdl2-image 2.0.3+dfsg1-3 MIGRATED to testing (Debian testing watch)
  • [2018-11-05] Accepted libsdl2-image 2.0.3+dfsg1-3 (source amd64) into unstable (Chris Lamb)
  • [2018-10-25] libsdl2-image 2.0.3+dfsg1-2 MIGRATED to testing (Debian testing watch)
  • [2018-10-19] Accepted libsdl2-image 2.0.3+dfsg1-2 (source amd64) into unstable (Manuel A. Fernandez Montecelo)
  • [2018-06-27] Accepted libsdl2-image 2.0.1+dfsg-2+deb9u1 (source) into proposed-updates->stable-new, proposed-updates (Felix Geyer)
  • [2018-04-22] Accepted libsdl2-image 2.0.0+dfsg-3+deb8u1 (source amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Felix Geyer)
  • [2018-04-19] Accepted libsdl2-image 2.0.1+dfsg-2+deb9u1 (source) into stable->embargoed, stable (Felix Geyer)
  • [2018-04-19] Accepted libsdl2-image 2.0.0+dfsg-3+deb8u1 (source amd64) into oldstable->embargoed, oldstable (Felix Geyer)
  • [2018-03-10] libsdl2-image 2.0.3+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • [2018-03-04] Accepted libsdl2-image 2.0.3+dfsg1-1 (source) into unstable (Felix Geyer)
  • [2017-11-15] libsdl2-image 2.0.2+dfsg1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, exp, clang, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.0.5+dfsg1-3build1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing