Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 22: 213788 Critical: Qt5 Remote Code Execution Risk

fedora
Calendar Grey April 21, 2015
Dist Fedora Esm H88
Various vulnerabilities in Qt's image handling could potentially result in service outages or heap corruption threats. Urgent patches released immediately.
Multiple vulnerabilities were found in Qt image format handling of BMP, ICO and GIF files

Summary

Qt is a software toolkit for developing applications.

This package contains base tools, like string, xml, and network

handling.

Update Information:

Multiple vulnerabilities were found in Qt image format handling of BMP, ICO and GIF files. The issues exposed included denial of service and buffer overflows leading to heap corruption. It is possible the latter could be used to perform remote code execution.

See also https://lists.qt-project.org/pipermail/announce/2015-April/000067.html

Drop backported Qt 5.5 XCB patches, the rebase is incomplete and does not work properly with Qt 5.4

Change Log

References


[ 1 ] Bug #1210675 - CVE-2015-1860 qt: segmentation fault in qgifhandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210675 [ 2 ] Bug #1210674 - CVE-2015-1859 qt: segmentation fault in qicohandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210674 [ 3 ] Bug #1210673 - CVE-2015-1858 qt: segmentation fault in qbmphandler.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1210673

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update qt5-qtbase' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: qt5-qtbase
Product: Fedora 22
Version: 5.4.1
Release: 9.fc22
Summary: Qt5 - QtBase components

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here