Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 21: FEDORA-2015-6252 Critical: qt Segmentation Faults

fedora
Calendar Grey April 30, 2015
Dist Fedora Esm H88
Patch release for Fedora 21 that resolves urgent vulnerabilities within the qt framework, aiming to eliminate segmentation violation errors identified in various CVEs.
Security fix for CVE-2015-1859, CVE-2015-1858, CVE-2015-1860

Summary

Qt is a software toolkit for developing applications.

This package contains base tools, like string, xml, and network

handling.

Update Information:

Security fix for CVE-2015-1859, CVE-2015-1858, CVE-2015-1860

Change Log

* Mon Apr 13 2015 Than Ngo - 1:4.8.6-28 - bz#1210677, CVE-2015-1860 CVE-2015-1859 CVE-2015-1858 * Thu Mar 26 2015 Richard Hughes - 1:4.8.6-27 - Add an AppData file for the software center * Fri Mar 20 2015 Rex Dieter 1:4.8.6-26 - macros.qt4: fix _qt4_evr macro (missing : after epoch) * Fri Feb 27 2015 Rex Dieter 1:4.8.6-25 - DoS vulnerability in the BMP image handler (CVE-2015-0295) * Mon Feb 16 2015 Rex Dieter 1:4.8.6-24 - more gcc5 detection fixes, in particular, ensure same QT_BUILD_KEY as gcc4 for now * Fri Feb 13 2015 Rex Dieter - 1:4.8.6-23 - Qt: FTBFS with gcc5 (#1192464) - Make Adwaita the default theme for applications running in the GNOME DE (#1192453) * Wed Feb 11 2015 Rex Dieter 1:4.8.6-22 - rebuild (gcc5) * Thu Jan 29 2015 Rex Dieter 1:4.8.6-21 - refresh boost/moc patch (QTBUG-22829) * Sun Jan 18 2015 Rex Dieter 1:4.8.6-20 - fix %pre scriptlet (#1183299) * Sat Jan 17 2015 Rex Dieter 1:4.8.6-19 - ship /etc/xdg/qtchooser/4.conf alternative instead (of qt4.conf) * Wed Nov 26 2014 Rex Dieter 1:4.8.6-18 - omit previously-overlooked webkit bits (#1168259) * Sun Nov 9 2014 Rex Dieter 1:4.8.6-17 - Broken qmake_qt4 in /usr/lib/rpm/macros.d/macros.qt4 (#1161927) * Mon Nov 3 2014 Rex Dieter 1:4.8.6-16 - macros.qt4: standalone, improved %qmake_qt4 macro (sync'd with qt5 version) * Sat Nov 1 2014 Kevin Kofler - 1:4.8.6-15 - sync system-clucene patch from qt5-qttools (some QDir::mkpath in QtCLucene) * Sun Oct 26 2014 Kevin Kofler - 1:4.8.6-14 - build against the system clucene09-core (same patch as for qt5-qttools)

References


[ 1 ] Bug #1210673 - CVE-2015-1858 qt: segmentation fault in qbmphandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210673 [ 2 ] Bug #1210674 - CVE-2015-1859 qt: segmentation fault in qicohandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210674 [ 3 ] Bug #1210675 - CVE-2015-1860 qt: segmentation fault in qgifhandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210675

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update qt' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: qt
Product: Fedora 21
Version: 4.8.6
Release: 28.fc21
Summary: Qt toolkit

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here