CVE-2018-19870: Null Pointer Dereference
A possible QImage allocation failure was found in qgifhandler. A crafted file could cause the application to crash.
Upstream patch:
https://codereview.qt-project.org/#/c/235998/
Other sources
An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19870?
CVE-2018-19870 is a vulnerability in Qt before version 5.11.3 that allows a malformed GIF image to cause a NULL pointer dereference, resulting in a segmentation fault.
How severe is CVE-2018-19870?
CVE-2018-19870 has a severity rating of high with a CVSS score of 8.8.
How does CVE-2018-19870 affect Qt?
CVE-2018-19870 affects Qt versions before 5.11.3.
How can I fix CVE-2018-19870?
To fix CVE-2018-19870, update Qt to version 5.11.3 or later.
Where can I find more information about CVE-2018-19870?
You can find more information about CVE-2018-19870 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00080.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00080.html), [https://access.redhat.com/errata/RHSA-2019:2135](https://access.redhat.com/errata/RHSA-2019:2135), [https://access.redhat.com/errata/RHSA-2019:3390](https://access.redhat.com/errata/RHSA-2019:3390).