First published: Thu Dec 13 2018(Updated: )
A possible QBpmHandler segmentation fault on malformed BMP file. A crafted filed could cause the application to crash. Upstream patch: <a href="https://codereview.qt-project.org/#/c/238749/">https://codereview.qt-project.org/#/c/238749/</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | <5.11.3 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =42.3 | |
ubuntu/qtbase-opensource-src | <5.9.5+dfsg-0ubuntu2.1 | 5.9.5+dfsg-0ubuntu2.1 |
ubuntu/qtbase-opensource-src | <5.11.1+dfsg-7ubuntu3.1 | 5.11.1+dfsg-7ubuntu3.1 |
ubuntu/qtbase-opensource-src | <5.11.3+dfsg-2ubuntu1 | 5.11.3+dfsg-2ubuntu1 |
ubuntu/qtbase-opensource-src | <5.11.3 | 5.11.3 |
ubuntu/qtbase-opensource-src | <5.5.1+dfsg-16ubuntu7.6 | 5.5.1+dfsg-16ubuntu7.6 |
debian/qtbase-opensource-src | 5.15.2+dfsg-9+deb11u1 5.15.8+dfsg-11+deb12u2 5.15.13+dfsg-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19873 is a vulnerability in Qt before 5.11.3 that allows a buffer overflow via BMP data.
The severity of CVE-2018-19873 is critical with a CVSS score of 9.8.
Qt versions before 5.11.3 are affected by CVE-2018-19873.
To fix CVE-2018-19873, update Qt to version 5.11.3 or later.
More information about CVE-2018-19873 can be found at the following references: [reference links].