ALINUX2-SA-2020%3A0049
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-15518: QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document. CVE-2018-19869: An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp. CVE-2018-19870: An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault. CVE-2018-19871: An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption. CVE-2018-19872: An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp. CVE-2018-19873: An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | qt |
Timeline
- Apr 2, 2020 CVE Published
- Apr 2, 2020 CVE Updated
References
- ALINUX2-SA-2020:0049: qt security update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15518 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19869 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19871 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19873 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19870 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19872 advisory