Update Info

openSUSE-2017-1217


Security update for SDL2


Type: security
Severity: moderate
Issued: 2017-10-27
Description:
This update for SDL2 fixes the following issues:

- CVE-2017-2888: An exploitable integer overflow vulnerability exists
  when creating a new RGB Surface in SDL. A specially crafted file can cause
  an integer overflow resulting in too little memory being allocated which
  can lead to a buffer overflow and potential code execution. An attacker
  can provide a specially crafted image file to trigger this vulnerability. (bsc#1062784)


              

Packages


  • SDL2-2.0.5-7.1