First published: Thu Dec 13 2018(Updated: )
A possible QImage allocation failure was found in qgifhandler. A crafted file could cause the application to crash. Upstream patch: <a href="https://codereview.qt-project.org/#/c/235998/">https://codereview.qt-project.org/#/c/235998/</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | <5.11.3 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.0 | |
ubuntu/qtbase-opensource-src | <5.9.5+dfsg-0ubuntu2.1 | 5.9.5+dfsg-0ubuntu2.1 |
ubuntu/qtbase-opensource-src | <5.11.1+dfsg-7ubuntu3.1 | 5.11.1+dfsg-7ubuntu3.1 |
ubuntu/qtbase-opensource-src | <5.11.3+dfsg-2ubuntu1 | 5.11.3+dfsg-2ubuntu1 |
ubuntu/qtbase-opensource-src | <5.11.3 | 5.11.3 |
ubuntu/qtbase-opensource-src | <5.5.1+dfsg-16ubuntu7.6 | 5.5.1+dfsg-16ubuntu7.6 |
debian/qtbase-opensource-src | 5.15.2+dfsg-9+deb11u1 5.15.8+dfsg-11+deb12u2 5.15.13+dfsg-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19870 is a vulnerability in Qt before version 5.11.3 that allows a malformed GIF image to cause a NULL pointer dereference, resulting in a segmentation fault.
CVE-2018-19870 has a severity rating of high with a CVSS score of 8.8.
CVE-2018-19870 affects Qt versions before 5.11.3.
To fix CVE-2018-19870, update Qt to version 5.11.3 or later.
You can find more information about CVE-2018-19870 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00080.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00080.html), [https://access.redhat.com/errata/RHSA-2019:2135](https://access.redhat.com/errata/RHSA-2019:2135), [https://access.redhat.com/errata/RHSA-2019:3390](https://access.redhat.com/errata/RHSA-2019:3390).