Debian Package Tracker
Register | Log in
Subscribe

sdl-image1.2

Choose email to subscribe with

general
  • source: sdl-image1.2 (main)
  • version: 1.2.12-14
  • maintainer: Debian SDL packages maintainers (archive) (DMD)
  • uploaders: Manuel A. Fernandez Montecelo [DMD] – Felix Geyer [DMD]
  • arch: any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.2.12-12
  • oldstable: 1.2.12-13
  • stable: 1.2.12-14
  • testing: 1.2.12-14
  • unstable: 1.2.12-14
versioned links
  • 1.2.12-12: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.12-13: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.2.12-14: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libsdl-image1.2
  • libsdl-image1.2-dev
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-35444: SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
Created: 2026-04-07 Last update: 2026-04-29 12:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-35444: SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
Created: 2026-04-07 Last update: 2026-04-29 12:30
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 1.2.12-15, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit b24f2cb90b3bd79b1e36a2a5ac95f2e80859633a
Author: Simon McVittie <smcv@debian.org>
Date:   Tue Nov 4 11:09:38 2025 +0000

    Update changelog

commit 32388cefd6a1e1b87e6af4967221a70515df3348
Author: Simon McVittie <smcv@debian.org>
Date:   Tue Nov 4 10:58:14 2025 +0000

    d/salsa-ci.yml: Add
Created: 2025-11-04 Last update: 2026-06-29 12:01
lintian reports 11 warnings normal
Lintian reports 11 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2024-07-26 Last update: 2026-02-28 06:30
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2025-08-19 Last update: 2025-08-19 06:28
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2026-35444: (needs triaging) SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-04-07 Last update: 2026-04-29 12:30
debian/patches: 6 patches to forward upstream low

Among the 24 debian patches available in version 1.2.12-14 of the package, we noticed the following issues:

  • 6 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2024-07-26 11:16
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.0).
Created: 2025-02-21 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2024-07-31] sdl-image1.2 1.2.12-14 MIGRATED to testing (Debian testing watch)
  • [2024-07-26] Accepted sdl-image1.2 1.2.12-14 (source) into unstable (Simon McVittie)
  • [2021-12-09] sdl-image1.2 1.2.12-13 MIGRATED to testing (Debian testing watch)
  • [2021-12-03] Accepted sdl-image1.2 1.2.12-13 (source) into unstable (Simon McVittie)
  • [2019-09-24] sdl-image1.2 1.2.12-12 MIGRATED to testing (Debian testing watch)
  • [2019-09-18] Accepted sdl-image1.2 1.2.12-12 (source) into unstable (Felix Geyer)
  • [2019-08-31] Accepted sdl-image1.2 1.2.12-5+deb9u2 (source amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Hugo Lefeuvre)
  • [2019-08-31] Accepted sdl-image1.2 1.2.12-10+deb10u1 (source amd64) into proposed-updates->stable-new, proposed-updates (Hugo Lefeuvre)
  • [2019-08-13] sdl-image1.2 1.2.12-11 MIGRATED to testing (Debian testing watch)
  • [2019-08-08] Accepted sdl-image1.2 1.2.12-11 (source) into unstable (Hugo Lefeuvre)
  • [2019-07-27] Accepted sdl-image1.2 1.2.12-5+deb8u2 (source amd64) into oldoldstable (Hugo Lefeuvre)
  • [2018-11-10] sdl-image1.2 1.2.12-10 MIGRATED to testing (Debian testing watch)
  • [2018-11-05] Accepted sdl-image1.2 1.2.12-10 (source amd64) into unstable (Chris Lamb)
  • [2018-10-29] sdl-image1.2 1.2.12-9 MIGRATED to testing (Debian testing watch)
  • [2018-10-23] Accepted sdl-image1.2 1.2.12-9 (source amd64) into unstable (Manuel A. Fernandez Montecelo)
  • [2018-04-30] Accepted sdl-image1.2 1.2.12-5+deb8u1 (source amd64) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Felix Geyer)
  • [2018-04-30] Accepted sdl-image1.2 1.2.12-5+deb9u1 (source) into proposed-updates->stable-new, proposed-updates (Felix Geyer)
  • [2018-04-28] Accepted sdl-image1.2 1.2.12-5+deb9u1 (source) into stable->embargoed, stable (Felix Geyer)
  • [2018-04-28] Accepted sdl-image1.2 1.2.12-5+deb8u1 (source amd64) into oldstable->embargoed, oldstable (Felix Geyer)
  • [2018-04-06] Accepted sdl-image1.2 1.2.12-2+deb7u2 (source amd64) into oldoldstable (Markus Koschany)
  • [2018-03-08] sdl-image1.2 1.2.12-8 MIGRATED to testing (Debian testing watch)
  • [2018-03-05] Accepted sdl-image1.2 1.2.12-8 (source) into unstable (Felix Geyer)
  • [2017-10-24] sdl-image1.2 1.2.12-7 MIGRATED to testing (Debian testing watch)
  • [2017-10-18] Accepted sdl-image1.2 1.2.12-7 (source) into unstable (Felix Geyer)
  • [2017-10-16] Accepted sdl-image1.2 1.2.12-2+deb7u1 (source amd64) into oldoldstable (Chris Lamb)
  • [2017-08-09] sdl-image1.2 1.2.12-6 MIGRATED to testing (Debian testing watch)
  • [2017-08-03] Accepted sdl-image1.2 1.2.12-6 (source amd64) into unstable (Manuel A. Fernandez Montecelo)
  • [2013-09-12] sdl-image1.2 1.2.12-5 MIGRATED to testing (Debian testing watch)
  • [2013-09-01] Accepted sdl-image1.2 1.2.12-5 (source amd64) (Felix Geyer)
  • [2013-08-12] sdl-image1.2 1.2.12-4 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 11)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.2.12-14build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing