Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 7: 2020-0204 Moderate Security Flaw in qt4 XML Parsing

mageia
Calendar Grey May 8, 2020
Dist Mageia Esm H88
Latest qt4 updates rectify several security vulnerabilities linked to XML parsing and image processing. Explore the detailed patches in the advisory released by Mageia.
Updated qt4 packages fix security vulnerabilities: A double-free or corruption during parsing of a specially crafted illegal XML document (CVE-2018-15518)

Summary

Updated qt4 packages fix security vulnerabilities:
A double-free or corruption during parsing of a specially crafted illegal XML document (CVE-2018-15518).
A malformed SVG image could cause a segmentation fault in qsvghandler.cpp (CVE-2018-19869).
A malformed GIF image might have caused a NULL pointer dereference in QGifHandler resulting in a segmentation fault (CVE-2018-19870).
There was an uncontrolled resource consumption in QTgaFile (CVE-2018-19871).
QBmpHandler had a buffer overflow via BMP data (CVE-2018-19873).

References

- https://bugs.mageia.org/show_bug.cgi?id=26505

- https://lists.debian.org/debian-lts-announce/2019/05/msg00014.html

- https://www.cve.org/CVERecord?id=CVE-2018-15518

- https://www.cve.org/CVERecord?id=CVE-2018-19869

- https://www.cve.org/CVERecord?id=CVE-2018-19870

- https://www.cve.org/CVERecord?id=CVE-2018-19871

- https://www.cve.org/CVERecord?id=CVE-2018-19873

Resolution

SRPMS

- 7/core/qt4-4.8.7-26.1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 08 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0204.html
Type: security
CVE: CVE-2018-15518, CVE-2018-19869, CVE-2018-19870, CVE-2018-19871, CVE-2018-19873

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here