--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2015-6364
2015-04-18 05:43:29
--------------------------------------------------------------------------------

Name        : qt5-qtbase
Product     : Fedora 21
Version     : 5.4.1
Release     : 9.fc21
URL         : https://contribute.qt-project.org/
Summary     : Qt5 - QtBase components
Description :
Qt is a software toolkit for developing applications.

This package contains base tools, like string, xml, and network
handling.

--------------------------------------------------------------------------------
Update Information:

Multiple vulnerabilities were found in Qt image format handling of  BMP, ICO and GIF files.  The issues exposed included denial of service and buffer overflows leading to heap corruption.  It is possible the latter could be used to perform remote code execution.

See also https://lists.qt-project.org/pipermail/announce/2015-April/000067.html
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 13 2015 Rex Dieter  5.4.1-9
- Multiple Vulnerabilities in Qt Image Format Handling (CVE-2015-1860 CVE-2015-1859 CVE-2015-1858)
* Fri Apr 10 2015 Rex Dieter  - 5.4.1-8
- -dbus=runtime on el6 (#1196359)
- %build: -no-directfb
* Wed Apr  1 2015 Daniel Vrátil  - 5.4.1-7
- drop 5.5 XCB patches, the rebase is incomplete and does not work properly with Qt 5.4
* Mon Mar 30 2015 Rex Dieter  5.4.1-6
- Crash due to unsafe access to QTextLayout::lineCount (#1207279,QTBUG-43562)
* Mon Mar 30 2015 Rex Dieter  5.4.1-5
- unable to use input methods in ibus-1.5.10 (#1203575)
* Wed Mar 25 2015 Daniel Vrátil  - 5.4.1-4
- pull in set of upstream Qt 5.5 fixes and improvements for XCB screen handling rebased to 5.4
* Fri Feb 27 2015 Rex Dieter  - 5.4.1-3
- pull in handful of upstream fixes, particularly...
- Fix a division by zero when processing malformed BMP files (QTBUG-44547, CVE-2015-0295)
* Wed Feb 25 2015 Rex Dieter  5.4.1-2
- try bootstrap=1 (f23)
* Tue Feb 24 2015 Jan Grulich  5.4.1-1
- update to 5.4.1
* Mon Feb 16 2015 Rex Dieter  5.4.0-13
- -no-use-gold-linker (f22+, #1193044)
* Thu Feb 12 2015 Rex Dieter  5.4.0-12
- own  %{_qt5_plugindir}/{designer,iconengines,script,styles}
* Thu Feb  5 2015 David Tardon  - 5.4.0-11
- full build after ICU soname bump
* Wed Feb  4 2015 Petr Machata  - 5.4.0-10
- Bump for rebuild.
* Sat Jan 31 2015 Rex Dieter  5.4.0-9
- crashes when connecting/disconnecting displays (#1083664,QTBUG-42985)
* Tue Jan 27 2015 David Tardon  - 5.4.0-8
- full build
* Mon Jan 26 2015 David Tardon  - 5.4.0-7
- rebuild for ICU 54.1
* Sun Jan 18 2015 Rex Dieter  5.4.0-6
- fix %pre scriptlet
* Sat Jan 17 2015 Rex Dieter  5.4.0-5
- ship /etc/xdg/qtchooser/5.conf alternative instead (of qt5.conf)
* Wed Dec 17 2014 Rex Dieter  5.4.0-4
- workaround 'make docs' crasher on el6 (QTBUG-43057)
* Thu Dec 11 2014 Rex Dieter  5.4.0-3
- don't omit examples for bootstrap (needs work)
* Wed Dec 10 2014 Rex Dieter  5.4.0-2
- fix bootstrapping logic
* Wed Dec 10 2014 Rex Dieter  5.4.0-1
- 5.4.0 (final)
* Fri Nov 28 2014 Rex Dieter  5.4.0-0.8.rc
- restore font rendering patch (#1052389,QTBUG-41590)
* Thu Nov 27 2014 Rex Dieter  5.4.0-0.7.rc
- 5.4.0-rc
* Wed Nov 12 2014 Rex Dieter  5.4.0-0.6.beta
- add versioned Requires: libxkbcommon dep
* Tue Nov 11 2014 Rex Dieter  5.4.0-0.5.beta
- pull in slightly different upstreamed font rendering fix (#1052389,QTBUG-41590)
* Mon Nov 10 2014 Rex Dieter  5.4.0-0.4.beta
- Bad font rendering (#1052389,QTBUG-41590)
* Mon Nov  3 2014 Rex Dieter  5.4.0-0.3.beta
- macros.qt5: +%qmake_qt5 , to help set standard build flags (CFLAGS, etc...)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1210675 - CVE-2015-1860 qt: segmentation fault in qgifhandler.cpp
        https://bugzilla.redhat.com/show_bug.cgi?id=1210675
  [ 2 ] Bug #1210674 - CVE-2015-1859 qt: segmentation fault in qicohandler.cpp
        https://bugzilla.redhat.com/show_bug.cgi?id=1210674
  [ 3 ] Bug #1210673 - CVE-2015-1858 qt: segmentation fault in qbmphandler.cpp
        https://bugzilla.redhat.com/show_bug.cgi?id=1210673
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update qt5-qtbase' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/

Fedora 21: qt5-qtbase Security Update

April 26, 2015
Multiple vulnerabilities were found in Qt image format handling of BMP, ICO and GIF files

Summary

Qt is a software toolkit for developing applications.

This package contains base tools, like string, xml, and network

handling.

Update Information:

Multiple vulnerabilities were found in Qt image format handling of BMP, ICO and GIF files. The issues exposed included denial of service and buffer overflows leading to heap corruption. It is possible the latter could be used to perform remote code execution.

See also https://lists.qt-project.org/pipermail/announce/2015-April/000067.html

Change Log

* Mon Apr 13 2015 Rex Dieter 5.4.1-9 - Multiple Vulnerabilities in Qt Image Format Handling (CVE-2015-1860 CVE-2015-1859 CVE-2015-1858) * Fri Apr 10 2015 Rex Dieter - 5.4.1-8 - -dbus=runtime on el6 (#1196359) - %build: -no-directfb * Wed Apr 1 2015 Daniel Vrátil - 5.4.1-7 - drop 5.5 XCB patches, the rebase is incomplete and does not work properly with Qt 5.4 * Mon Mar 30 2015 Rex Dieter 5.4.1-6 - Crash due to unsafe access to QTextLayout::lineCount (#1207279,QTBUG-43562) * Mon Mar 30 2015 Rex Dieter 5.4.1-5 - unable to use input methods in ibus-1.5.10 (#1203575) * Wed Mar 25 2015 Daniel Vrátil - 5.4.1-4 - pull in set of upstream Qt 5.5 fixes and improvements for XCB screen handling rebased to 5.4 * Fri Feb 27 2015 Rex Dieter - 5.4.1-3 - pull in handful of upstream fixes, particularly... - Fix a division by zero when processing malformed BMP files (QTBUG-44547, CVE-2015-0295) * Wed Feb 25 2015 Rex Dieter 5.4.1-2 - try bootstrap=1 (f23) * Tue Feb 24 2015 Jan Grulich 5.4.1-1 - update to 5.4.1 * Mon Feb 16 2015 Rex Dieter 5.4.0-13 - -no-use-gold-linker (f22+, #1193044) * Thu Feb 12 2015 Rex Dieter 5.4.0-12 - own %{_qt5_plugindir}/{designer,iconengines,script,styles} * Thu Feb 5 2015 David Tardon - 5.4.0-11 - full build after ICU soname bump * Wed Feb 4 2015 Petr Machata - 5.4.0-10 - Bump for rebuild. * Sat Jan 31 2015 Rex Dieter 5.4.0-9 - crashes when connecting/disconnecting displays (#1083664,QTBUG-42985) * Tue Jan 27 2015 David Tardon - 5.4.0-8 - full build * Mon Jan 26 2015 David Tardon - 5.4.0-7 - rebuild for ICU 54.1 * Sun Jan 18 2015 Rex Dieter 5.4.0-6 - fix %pre scriptlet * Sat Jan 17 2015 Rex Dieter 5.4.0-5 - ship /etc/xdg/qtchooser/5.conf alternative instead (of qt5.conf) * Wed Dec 17 2014 Rex Dieter 5.4.0-4 - workaround 'make docs' crasher on el6 (QTBUG-43057) * Thu Dec 11 2014 Rex Dieter 5.4.0-3 - don't omit examples for bootstrap (needs work) * Wed Dec 10 2014 Rex Dieter 5.4.0-2 - fix bootstrapping logic * Wed Dec 10 2014 Rex Dieter 5.4.0-1 - 5.4.0 (final) * Fri Nov 28 2014 Rex Dieter 5.4.0-0.8.rc - restore font rendering patch (#1052389,QTBUG-41590) * Thu Nov 27 2014 Rex Dieter 5.4.0-0.7.rc - 5.4.0-rc * Wed Nov 12 2014 Rex Dieter 5.4.0-0.6.beta - add versioned Requires: libxkbcommon dep * Tue Nov 11 2014 Rex Dieter 5.4.0-0.5.beta - pull in slightly different upstreamed font rendering fix (#1052389,QTBUG-41590) * Mon Nov 10 2014 Rex Dieter 5.4.0-0.4.beta - Bad font rendering (#1052389,QTBUG-41590) * Mon Nov 3 2014 Rex Dieter 5.4.0-0.3.beta - macros.qt5: +%qmake_qt5 , to help set standard build flags (CFLAGS, etc...)

References

[ 1 ] Bug #1210675 - CVE-2015-1860 qt: segmentation fault in qgifhandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210675 [ 2 ] Bug #1210674 - CVE-2015-1859 qt: segmentation fault in qicohandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210674 [ 3 ] Bug #1210673 - CVE-2015-1858 qt: segmentation fault in qbmphandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210673

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update qt5-qtbase' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : qt5-qtbase
Product : Fedora 21
Version : 5.4.1
Release : 9.fc21
URL : https://contribute.qt-project.org/
Summary : Qt5 - QtBase components

Related News