openSUSE: 2025:0039-1 important: stb Advisory Security Update
Description
This update for stb fixes the following issues: Addressing the follow security issues (boo#1216478): * CVE-2019-13217: heap buffer overflow in start_decoder() * CVE-2019-13218: stack buffer overflow in compute_codewords() * CVE-2019-13219: uninitialized memory in vorbis_decode_packet_rest() * CVE-2019-13220: out-of-range read in draw_line() * CVE-2019-13221: issue with large 1D codebooks in lookup1_values() * CVE-2019-13222: unchecked NULL returned by get_window() * CVE-2019-13223: division by zero in predict_point()
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-39=1
Package List
- openSUSE Backports SLE-15-SP6 (noarch): stb-devel-20240910-bp156.2.3.1
References
https://www.suse.com/security/cve/CVE-2019-13217.html https://www.suse.com/security/cve/CVE-2019-13218.html https://www.suse.com/security/cve/CVE-2019-13219.html https://www.suse.com/security/cve/CVE-2019-13220.html https://www.suse.com/security/cve/CVE-2019-13221.html https://www.suse.com/security/cve/CVE-2019-13222.html https://www.suse.com/security/cve/CVE-2019-13223.html https://bugzilla.suse.com/1216478
![Dist Opensuse](/images/distros/dist-opensuse.jpg)