Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide a release with a fix for CVE-2018-25032 #198

Closed
dvrogozh opened this issue Apr 21, 2022 · 5 comments
Closed

Provide a release with a fix for CVE-2018-25032 #198

dvrogozh opened this issue Apr 21, 2022 · 5 comments
Assignees
Milestone

Comments

@dvrogozh
Copy link

There is CVE-2018-25032 reported against zlib which is included into SDL_ttf releleases. Affected zlib version is 1.2.11, fix available in 1.2.12. See madler/zlib#605.

Can you, please, provide SDL_ttf release which includes a fix for zlib CVE?

@slouken slouken added this to the 2.20.0 milestone May 25, 2022
@slouken slouken self-assigned this May 25, 2022
@slouken
Copy link
Collaborator

slouken commented Jun 28, 2022

@madebr, just a sanity check, do you know of anything that needs to be done before final release?

@sezero
Copy link
Contributor

sezero commented Jul 7, 2022

@slouken: Debian applies this patch to freetype-2.12.1 to fix a 'wild free'
issue: Do we want to cherry-pick it?
libsdl-org/freetype@c26872e

@slouken
Copy link
Collaborator

slouken commented Jul 7, 2022

Yes, let's grab it for the final release today.

@slouken
Copy link
Collaborator

slouken commented Jul 7, 2022

It's in now, thanks!

@slouken
Copy link
Collaborator

slouken commented Jul 7, 2022

2.20.0 with a fix for CVE-2018-25032 is now available!
https://github.com/libsdl-org/SDL_ttf/releases/tag/release-2.20.0

@slouken slouken closed this as completed Jul 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants