CVE-2018-19873: Buffer Overflow
Published Dec 13, 2018
·Updated
A possible QBpmHandler segmentation fault on malformed BMP file. A crafted filed could cause the application to crash.
Upstream patch:
https://codereview.qt-project.org/#/c/238749/
Other sources
An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
— Launchpad
Affected Software
15 affected componentsFixes available
debian/qtbase-opensource-src
5.15.2+dfsg-9+deb11u15.15.8+dfsg-11+deb12u25.15.15+dfsg-4
Qt QT<=5.5.1
Qt QT>=5.7.0<=5.8.0
Qt QT>=5.10.0<5.11.3
openSUSE Backports=sle-15-sp1
openSUSE Backports=sle-15-sp2
openSUSE Leap=15.1
openSUSE Leap=15.2
openSUSE Leap=42.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=18.10
Qt QT<5.11.3
Remediation
Patch Available
Event History
Dec 13, 2018
Data Sourced
via Red Hat·10:55 AM
DescriptionSeverityAffected Software
Dec 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:58 PM
Description
Feb 16, 2025
Data Sourced
via Ubuntu·07:37 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2018-19873?
CVE-2018-19873 is a vulnerability in Qt before 5.11.3 that allows a buffer overflow via BMP data.
2
What is the severity of CVE-2018-19873?
The severity of CVE-2018-19873 is critical with a CVSS score of 9.8.
3
What software is affected by CVE-2018-19873?
Qt versions before 5.11.3 are affected by CVE-2018-19873.
4
How do I fix CVE-2018-19873?
To fix CVE-2018-19873, update Qt to version 5.11.3 or later.
5
Where can I find more information about CVE-2018-19873?
More information about CVE-2018-19873 can be found at the following references: [reference links].