Debian Security Advisory

DLA-1134-1 sdl-image1.2 -- LTS security update

Date Reported:
16 Oct 2017
Affected Packages:
sdl-image1.2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-2887.
More information:

It was discovered that there was a buffer overflow vulnerability in sdl-image1.2, an image loading library.

A specially crafted .xcf file could cause a stack-based buffer overflow resulting in potential code execution.

For Debian 7 Wheezy, this issue has been fixed in sdl-image1.2 version 1.2.12-2+deb7u1.

We recommend that you upgrade your sdl-image1.2 packages.