{"id":"openSUSE-SU-2018:3906-1","summary":"Security update for SDL2_image","details":"This update for SDL2_image fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2018-3839: Fixed an exploitable code execution vulnerability that existed in the XCF image rendering functionality of the Simple DirectMedia Layer (bsc#1089087).\n- CVE-2018-3977: Fixed a possible code execution via creafted XCF image that could have caused a heap overflow (bsc#1114519).\n\nThis update was imported from the openSUSE:Leap:15.0:Update update project.","modified":"2026-03-11T07:32:01.189903Z","published":"2018-11-24T17:19:59Z","related":["CVE-2018-3839","CVE-2018-3977"],"upstream":["CVE-2018-3839","CVE-2018-3977"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HQVNFPNLELYLGSLFGHD2PGATNGD5RZRD/#HQVNFPNLELYLGSLFGHD2PGATNGD5RZRD"},{"type":"REPORT","url":"https://bugzilla.suse.com/1089087"},{"type":"REPORT","url":"https://bugzilla.suse.com/1114519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-3839"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-3977"}],"affected":[{"package":{"name":"SDL2_image","ecosystem":"SUSE:Package Hub 15","purl":"pkg:rpm/suse/SDL2_image&distro=SUSE%20Package%20Hub%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.4-bp150.3.3.1"}]}],"ecosystem_specific":{"binaries":[{"libSDL2_image-2_0-0-64bit":"2.0.4-bp150.3.3.1","libSDL2_image-2_0-0":"2.0.4-bp150.3.3.1","libSDL2_image-devel-64bit":"2.0.4-bp150.3.3.1","libSDL2_image-devel":"2.0.4-bp150.3.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:3906-1.json"}}],"schema_version":"1.7.5"}