First published: Fri Mar 15 2019(Updated: )
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | =5.11.0 | |
openSUSE Leap | =15.0 | |
Fedoraproject Fedora | =28 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
redhat/qt | <5.6.4 | 5.6.4 |
redhat/qt | <5.9.7 | 5.9.7 |
redhat/qt | <5.11.2 | 5.11.2 |
debian/qtbase-opensource-src | 5.15.2+dfsg-9+deb11u1 5.15.8+dfsg-11+deb12u2 5.15.13+dfsg-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19872 is a vulnerability in Qt 5.11 that allows a division by zero and causes a crash when processing a malformed PPM image.
The severity of CVE-2018-19872 is medium with a CVSS score of 5.5.
Qt versions 5.6.4, 5.9.7, and 5.11.2 are affected by CVE-2018-19872.
To fix CVE-2018-19872, update your Qt software to version 5.11.3 or higher.
You can find more information about CVE-2018-19872 in the references provided: http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/, http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00080.html, and https://bugreports.qt.io/browse/QTBUG-69449.