ALINUX2-SA-2019%3A0095
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-15518: QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document. CVE-2018-19869: An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp. CVE-2018-19870: An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault. CVE-2018-19871: An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption. CVE-2018-19873: An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | qt5-qtwebchannel | |
| Alibaba Cloud | qt5-qtwebsockets | |
| Alibaba Cloud | qt5-qtimageformats | |
| Alibaba Cloud | qt5-qttranslations | |
| Alibaba Cloud | qt5-qt3d | |
| Alibaba Cloud | qt5-qtquickcontrols | |
| Alibaba Cloud | qt5-qtmultimedia | |
| Alibaba Cloud | qt5-qtx11extras | |
| Alibaba Cloud | qt5-qtxmlpatterns | |
| Alibaba Cloud | qt5-qtsensors | |
| Alibaba Cloud | qt5-qtcanvas3d | |
| Alibaba Cloud | qt5-qtdeclarative | |
| Alibaba Cloud | qt5-qtserialbus | |
| Alibaba Cloud | qt5-qtsvg | |
| Alibaba Cloud | qt5-qtlocation | |
| Alibaba Cloud | qt5-qtwayland | |
| Alibaba Cloud | qt5-qtquickcontrols2 | |
| Alibaba Cloud | qt5-qtdoc | |
| Alibaba Cloud | qt5-qtserialport | |
| Alibaba Cloud | qt5-qtconnectivity |
…and 4 more
Timeline
- Oct 18, 2019 CVE Published
- Oct 18, 2019 CVE Updated
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19869 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19870 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19871 advisory
- ALINUX2-SA-2019:0095: qt5 security, bug fix, and enhancement update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15518 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19873 advisory