First published: Thu Dec 13 2018(Updated: )
A possible QBpmHandler segmentation fault on malformed BMP file. A crafted filed could cause the application to crash. Upstream patch: <a href="https://codereview.qt-project.org/#/c/238749/">https://codereview.qt-project.org/#/c/238749/</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/qtbase-opensource-src | 5.15.2+dfsg-9+deb11u1 5.15.8+dfsg-11+deb12u2 5.15.15+dfsg-4 | |
Trolltech Qt | <5.11.3 | |
Debian | =8.0 | |
Debian | =9.0 | |
SUSE Linux | =42.3 | |
Trolltech Qt | <=5.5.1 | |
Trolltech Qt | >=5.7.0<=5.8.0 | |
Trolltech Qt | >=5.10.0<5.11.3 | |
SUSE Backports | =sle-15-sp1 | |
SUSE Backports | =sle-15-sp2 | |
SUSE Linux | =15.1 | |
SUSE Linux | =15.2 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19873 is a vulnerability in Qt before 5.11.3 that allows a buffer overflow via BMP data.
The severity of CVE-2018-19873 is critical with a CVSS score of 9.8.
Qt versions before 5.11.3 are affected by CVE-2018-19873.
To fix CVE-2018-19873, update Qt to version 5.11.3 or later.
More information about CVE-2018-19873 can be found at the following references: [reference links].