CVE-2018-19871: Medium severity trolltech qt vulnerability
A TGA handler of QT imageformats incorrectly checks for large image sizes. A malformed image file could cause CPU exhaustion and denial of service.
References:
https://codereview.qt-project.org/#/c/237761/
Other sources
An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-19871?
CVE-2018-19871 is a vulnerability discovered in Qt before version 5.11.3 that allows uncontrolled resource consumption in QTgaFile.
What is the severity of CVE-2018-19871?
The severity of CVE-2018-19871 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2018-19871?
CVE-2018-19871 affects versions up to and excluding 5.11.3 of Qt and openSUSE Leap 15.0.
How can I fix CVE-2018-19871?
To fix CVE-2018-19871, upgrade to version 5.11.3 or later of Qt or apply the necessary patches provided by the respective vendors.
Where can I find more information about CVE-2018-19871?
More information about CVE-2018-19871 can be found at the following references: [1] [2] [3]