CVE-2019-12221 affects libsdl2-image/sdl-image1.2, not libsdl2/libsdl1.2


I investigated CVE-2019-12221[0] and found out that the issue lies in the
libsdl2-image/sdl-image1.2 codebase, not libsdl2/libsdl1.2.

I have temporarily added a NOTE to the tracker because I was not sure of
how to handle this[1]. Should I simply replace

[stretch] - libsdl2 <no-dsa>


[stretch] - libsdl2-image <no-dsa>

and same for libsdl1.2?


