CVE-2018-19872: Divide by Zero
Published Mar 15, 2019
·Updated
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
Affected Software
9 affected componentsFixes available
redhat/qt<5.6.4
5.6.4
redhat/qt<5.9.7
5.9.7
redhat/qt<5.11.2
5.11.2
Qt QT=5.11.0
openSUSE Leap=15.0
Fedoraproject Fedora=28
Fedoraproject Fedora=29
Fedoraproject Fedora=30
debian/qtbase-opensource-src
5.15.2+dfsg-9+deb11u15.15.2+dfsg-9+deb11u25.15.8+dfsg-11+deb12u35.15.15+dfsg-65.15.17+dfsg-7
Remediation
Patch Available
Event History
Mar 15, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Mar 21, 2019
Data Sourced
via NVD·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·06:35 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:36 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:36 PM
Description
Frequently Asked Questions
1
What is CVE-2018-19872?
CVE-2018-19872 is a vulnerability in Qt 5.11 that allows a division by zero and causes a crash when processing a malformed PPM image.
2
What is the severity of CVE-2018-19872?
The severity of CVE-2018-19872 is medium with a CVSS score of 5.5.
3
Which software versions are affected by CVE-2018-19872?
Qt versions 5.6.4, 5.9.7, and 5.11.2 are affected by CVE-2018-19872.
4
How can I fix CVE-2018-19872?
To fix CVE-2018-19872, update your Qt software to version 5.11.3 or higher.
5
Where can I find more information about CVE-2018-19872?
You can find more information about CVE-2018-19872 in the references provided: http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/, http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00080.html, and https://bugreports.qt.io/browse/QTBUG-69449.