Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:1665

Опубликовано: 28 апр. 2020
Источник: rocky
Оценка: Moderate

Описание

Moderate: qt5 security, bug fix, and enhancement update

Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.

The following packages have been upgraded to a later upstream version: qt5 (5.12.5), qt5-qt3d (5.12.5), qt5-qtbase (5.12.5), qt5-qtcanvas3d (5.12.5), qt5-qtconnectivity (5.12.5), qt5-qtdeclarative (5.12.5), qt5-qtdoc (5.12.5), qt5-qtgraphicaleffects (5.12.5), qt5-qtimageformats (5.12.5), qt5-qtlocation (5.12.5), qt5-qtmultimedia (5.12.5), qt5-qtquickcontrols (5.12.5), qt5-qtquickcontrols2 (5.12.5), qt5-qtscript (5.12.5), qt5-qtsensors (5.12.5), qt5-qtserialbus (5.12.5), qt5-qtserialport (5.12.5), qt5-qtsvg (5.12.5), qt5-qttools (5.12.5), qt5-qttranslations (5.12.5), qt5-qtwayland (5.12.5), qt5-qtwebchannel (5.12.5), qt5-qtwebsockets (5.12.5), qt5-qtx11extras (5.12.5), qt5-qtxmlpatterns (5.12.5), python-qt5 (5.13.1), sip (4.19.19). (BZ#1775603, BZ#1775604)

Security Fix(es):

  • qt: Malformed PPM image causing division by zero and crash in qppmhandler.cpp (CVE-2018-19872)

  • qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service (CVE-2018-19869)

  • qt5-qtimageformats: QTgaFile CPU exhaustion (CVE-2018-19871)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.2 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
python3-qt5i6861.el8python3-qt5-5.13.1-1.el8.i686.rpm
python3-qt5x86_641.el8python3-qt5-5.13.1-1.el8.x86_64.rpm
python3-qt5-basei6861.el8python3-qt5-base-5.13.1-1.el8.i686.rpm
python3-qt5-basex86_641.el8python3-qt5-base-5.13.1-1.el8.x86_64.rpm
python-qt5-rpm-macrosnoarch1.el8python-qt5-rpm-macros-5.13.1-1.el8.noarch.rpm
python-qt5-rpm-macrosnoarch1.el8python-qt5-rpm-macros-5.13.1-1.el8.noarch.rpm
qgnomeplatformi6863.el8qgnomeplatform-0.4-3.el8.i686.rpm
qgnomeplatformx86_643.el8qgnomeplatform-0.4-3.el8.x86_64.rpm
qt5-qt3di6862.el8qt5-qt3d-5.12.5-2.el8.i686.rpm
qt5-qt3dx86_642.el8qt5-qt3d-5.12.5-2.el8.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
почти 6 лет назад

ELSA-2020-1665: qt5 security, bug fix, and enhancement update (MODERATE)

oracle-oval
почти 6 лет назад

ELSA-2020-1172: qt security update (MODERATE)

oracle-oval
больше 6 лет назад

ELSA-2019-2135: qt5 security, bug fix, and enhancement update (MODERATE)

CVSS3: 6.5
ubuntu
около 7 лет назад

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

CVSS3: 3.3
redhat
больше 7 лет назад

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.