Debian 9890 Published by

The following security updates has been released for Debian GNU/Linux 7 LTS:

DLA 1340-1: sam2p security update
DLA 1341-1: sdl-image1.2 security update



DLA 1340-1: sam2p security update




Package : sam2p
Version : 0.49.1-1+deb7u3
CVE ID : CVE-2018-7487 CVE-2018-7551 CVE-2018-7552
CVE-2018-7553 CVE-2018-7554

Multiple invalid frees and buffer-overflow vulnerabilities were
discovered in sam2p, a utility to convert raster images and
other image formats, that may lead to a denial-of-service (application
crash) or unspecified other impact.

For Debian 7 "Wheezy", these problems have been fixed in version
0.49.1-1+deb7u3.

We recommend that you upgrade your sam2p packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


DLA 1341-1: sdl-image1.2 security update




Package : sdl-image1.2
Version : 1.2.12-2+deb7u2
CVE ID : CVE-2017-12122 CVE-2017-14440 CVE-2017-14441
CVE-2017-14442 CVE-2017-14448 CVE-2017-14450

Lilith of Cisco Talos discovered several buffer overflow
vulnerabilities in the SDL Image library which can be leveraged by
attackers to execute arbitrary code via specially crafted image files.

For Debian 7 "Wheezy", these problems have been fixed in version
1.2.12-2+deb7u2.

We recommend that you upgrade your sdl-image1.2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS