From nobody Mon Apr 22 18:20:32 2024 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4VNYTD3MdZz5HcTx; Mon, 22 Apr 2024 18:20:32 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4VNYTD1rpZz4X0h; Mon, 22 Apr 2024 18:20:32 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1713810032; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ns0iVMMcVQgeGsSUbP5fxLKezaT8P3xQ9r4kNcPMLwc=; b=gobYS/qW59kB31CD//rIab1a8+EDTeTd/uXS/r13GlvujSWbR7Wg/6qNfr1kfecLsZUsj/ na9lDesonQizr62yJ7tDv2KwzxqEa0KUr0na0LgDO2j9KNomPTXRi2A5+jyAaWEOU8BPPQ BYsnGn6lz7OhyqRa2gcVterbJ/U104jyzBF8Fs5j0dKOxwe4CPEoLBy0Udn6wpjIziW7a2 a0vcFFtKYWO0ZXzG7oCeYRr6IgEWv8diAp4/O1jijkTzaJ+uANbgwxEcs3rPFX26irfE+m hRbpZtroZD3R9QqFwN23M20myKtLPbSmw+ChsMVIm/TK5Wj/3Sbc8lpnBECC9w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1713810032; a=rsa-sha256; cv=none; b=p6ZlW3RGYMH1d3UOGcUcX4TYl4cCvuDdNzL/fZ4E/sc5evPCicPqf+eVhRXiD/8IwawI3a fNVtkIE+SNw+rHiQxk3YNiZx92SdHeChTllLcg2t/9FxD3rHkJyIJUvg9OFIquLN1jnYM6 nlQJGtyqBqck4rTg+XTRpXJwMDOsVTnVhjxsQ1QaCwu/op/yStHZyKPmVLmKpqNHMPDPE0 6UAxsonLTPRiPNFl1EEcJImoD7xo7Sw6voRhZE/Y1EADrb5hjHAF+APStCBUuGx1snfwjS gqjk2WxHEW4FY88grbN26wzrYz5J92pjR/B+1LqdqJXvCoIrcTFJSFXoDVXxqw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1713810032; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=ns0iVMMcVQgeGsSUbP5fxLKezaT8P3xQ9r4kNcPMLwc=; b=BHyQgU6Luo3joGq3WbbqQcuCWGMg/N/wpgasjqZAoz0GDd9ErEElCDatJuVtlggy0NIHk1 ZMjakYOYKn/oW/GJmoaZpJsBJA/4MOWZCaytc8iu5ueo3AmrrL5B2fYY73brCZb2FpgagF T8yiFxsxvBmxty7NAOM8q75XJTBIsuLv5qhgz+W4YwzH/eKZ4F/UQjWGVJTK+hopF3spuS B4DcJKoRwuE1GfOsvVrYjbgJQ6o8lDN9mH//mkxggjIg6wZj+Nr9YS5u7sAAaRPt7Ip1IK gJwYjF4orQHQW0nhhpEz9aEnwyf9xn79CTkTFl4GuvWCmGg73DhVUt8WoNbvow== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4VNYTD1B0dzyNw; Mon, 22 Apr 2024 18:20:32 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 43MIKWOc088940; Mon, 22 Apr 2024 18:20:32 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 43MIKW8i088937; Mon, 22 Apr 2024 18:20:32 GMT (envelope-from git) Date: Mon, 22 Apr 2024 18:20:32 GMT Message-Id: <202404221820.43MIKW8i088937@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Dmitry Marakasov Subject: git: a8b170fac8cb - main - security/vuxml: document sdl2_sound vulns List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: amdmi3 X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: a8b170fac8cbc8afc03645ea2a4a3de1f24e5699 Auto-Submitted: auto-generated The branch main has been updated by amdmi3: URL: https://cgit.FreeBSD.org/ports/commit/?id=a8b170fac8cbc8afc03645ea2a4a3de1f24e5699 commit a8b170fac8cbc8afc03645ea2a4a3de1f24e5699 Author: Dmitry Marakasov AuthorDate: 2024-04-22 16:39:15 +0000 Commit: Dmitry Marakasov CommitDate: 2024-04-22 18:20:02 +0000 security/vuxml: document sdl2_sound vulns PR: 278491 --- security/vuxml/vuln/2024.xml | 47 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index 1532c5caabbb..571f786f78be 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,50 @@ + + sdl2_sound -- multiple vulnerabilities + + + sdl2_sound + 2.0.2_1 + + + + +

GitHub Security Lab reports:

+
+

stb_image.h and stb_vorbis libraries contain several memory access violations of different severity

+
    +
  1. Wild address read in stbi__gif_load_next (GHSL-2023-145).
  2. +
  3. Multi-byte read heap buffer overflow in stbi__vertical_flip (GHSL-2023-146).
  4. +
  5. Disclosure of uninitialized memory in stbi__tga_load (GHSL-2023-147).
  6. +
  7. Double-free in stbi__load_gif_main_outofmem (GHSL-2023-148).
  8. +
  9. Null pointer dereference in stbi__convert_format (GHSL-2023-149).
  10. +
  11. Possible double-free or memory leak in stbi__load_gif_main (GHSL-2023-150).
  12. +
  13. Null pointer dereference because of an uninitialized variable (GHSL-2023-151).
  14. +
  15. 0 byte write heap buffer overflow in start_decoder (GHSL-2023-165)
  16. +
  17. Multi-byte write heap buffer overflow in start_decoder (GHSL-2023-166)
  18. +
  19. Heap buffer out of bounds write in start_decoder (GHSL-2023-167)
  20. +
  21. Off-by-one heap buffer write in start_decoder (GHSL-2023-168)
  22. +
  23. Attempt to free an uninitialized memory pointer in vorbis_deinit (GHSL-2023-169)
  24. +
  25. Null pointer dereference in vorbis_deinit (GHSL-2023-170)
  26. +
  27. Out of bounds heap buffer write (GHSL-2023-171)
  28. +
  29. Wild address read in vorbis_decode_packet_rest (GHSL-2023-172)
  30. +
+
+ +
+ + CVE-2023-45676 + CVE-2023-45677 + CVE-2023-45680 + CVE-2023-45681 + CVE-2023-45682 + https://securitylab.github.com/advisories/GHSL-2023-145_GHSL-2023-151_stb_image_h/ + + + 2023-10-20 + 2024-04-22 + +
+ chromium -- multiple security fixes