First published: Thu Dec 13 2018(Updated: )
A possible double free and heap corruption was found in QXmlStream. Upstream patch: <a href="https://codereview.qt-project.org/#/c/236691/">https://codereview.qt-project.org/#/c/236691/</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | >=5.5.0<5.11.3 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =42.3 | |
ubuntu/qtbase-opensource-src | <5.9.5+dfsg-0ubuntu2.1 | 5.9.5+dfsg-0ubuntu2.1 |
ubuntu/qtbase-opensource-src | <5.11.1+dfsg-7ubuntu3.1 | 5.11.1+dfsg-7ubuntu3.1 |
ubuntu/qtbase-opensource-src | <5.11.3+dfsg-2ubuntu1 | 5.11.3+dfsg-2ubuntu1 |
ubuntu/qtbase-opensource-src | <5.11.3 | 5.11.3 |
ubuntu/qtbase-opensource-src | <5.5.1+dfsg-16ubuntu7.6 | 5.5.1+dfsg-16ubuntu7.6 |
debian/qtbase-opensource-src | 5.15.2+dfsg-9+deb11u1 5.15.8+dfsg-11+deb12u2 5.15.13+dfsg-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15518 is a vulnerability in the QXmlStream component of Qt 5.x before 5.11.3 that allows for a double-free or corruption during parsing of a specially crafted illegal XML document.
CVE-2018-15518 has a severity rating of 8.8 (high).
Qt versions 5.9.5 and 5.11.1 are affected by CVE-2018-15518.
To fix CVE-2018-15518, it is recommended to update Qt to version 5.11.3 or later.
More information about CVE-2018-15518 can be found in the references provided: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2018-12/msg00066.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00057.html), [Reference 3](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00071.html).