Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-18281

Опубликовано: 23 окт. 2019
Источник: redhat
CVSS3: 4.3

Описание

An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.

Отчет

Red Hat Enterprise Linux 7 is not affected by this issue as qt5-base version as shipped with it doesn't have the code which contains the bug.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7qt5-qtbaseNot affected
Red Hat Enterprise Linux 8python-qt5FixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qgnomeplatformFixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5FixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5-qt3dFixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5-qtbaseFixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5-qtcanvas3dFixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5-qtconnectivityFixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5-qtdeclarativeFixedRHSA-2020:166529.04.2020
Red Hat Enterprise Linux 8qt5-qtdocFixedRHSA-2020:166529.04.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1764742qt5-qtbase: Out-of-bounds access in generateDirectionalRuns() function in qtextengine.cpp

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 6 лет назад

An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.

CVSS3: 4.3
nvd
больше 6 лет назад

An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.

CVSS3: 4.3
debian
больше 6 лет назад

An out-of-bounds memory access in the generateDirectionalRuns() functi ...

github
больше 3 лет назад

An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.

CVSS3: 4.3
fstec
больше 6 лет назад

Уязвимость функции generateDirectionalRuns() библиотеки Qt, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

4.3 Medium

CVSS3