CVE-2018-19865: High severity trolltech qt vulnerability
Published Dec 5, 2018
·Updated
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
Affected Software
6 affected components
Qt QT>=5.7.0<=5.7.1
Qt QT>=5.9.0<=5.9.7
Qt QT>=5.10.0<=5.10.1
Qt QT>=5.11.0<5.11.3
Qt QT=5.8.0
openSUSE Leap=15.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 5, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2018-19865.
2
What is the severity of CVE-2018-19865?
The severity of CVE-2018-19865 is high with a CVSS score of 7.5.
3
Which versions of Qt are affected by CVE-2018-19865?
Qt versions 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3 are affected by CVE-2018-19865.
4
How can I fix the keystroke logging issue in Virtual Keyboard in Qt?
To fix the keystroke logging issue, update to Qt version 5.11.3 or later.
5
Where can I find more information about CVE-2018-19865?
You can find more information about CVE-2018-19865 at the following references: [link1](http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/), [link2](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00085.html), [link3](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00086.html).