MGASA-2019-0025 - Updated qtbase5 packages fix security vulnerabilities

Publication date: 08 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0025.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-15518,
     CVE-2018-19873

Double free in QXmlStreamReader (CVE-2018-15518).

Denial of Service on malformed BMP file in QBmpHandler (CVE-2018-19873).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24081
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15518
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19873

SRPMS:
- 6/core/qtbase5-5.9.4-1.2.mga6

Mageia 2019-0025: qtbase5 security update

Double free in QXmlStreamReader (CVE-2018-15518)

Summary

Double free in QXmlStreamReader (CVE-2018-15518).
Denial of Service on malformed BMP file in QBmpHandler (CVE-2018-19873).

References

- https://bugs.mageia.org/show_bug.cgi?id=24081

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15518

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19873

Resolution

MGASA-2019-0025 - Updated qtbase5 packages fix security vulnerabilities

SRPMS

- 6/core/qtbase5-5.9.4-1.2.mga6

Severity
Publication date: 08 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0025.html
Type: security
CVE: CVE-2018-15518, CVE-2018-19873

Related News