Buffer overflow in Qt - CVE-2018-19873

 

Buffer overflow in Qt - CVE-2018-19873

Published: January 31, 2019


Vulnerability identifier: #VU17339
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19873
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to buffer overflow in QBmpHandler. A remote attacker can trick the victim into opening specially crafted BMP data, trigger memory corruption and cause the service to crash.


Affected software

Qt
qtbase-opensource-src (Ubuntu package)
qtbase-opensource-src (Debian package)
qt (Red Hat package)
mingw-sip
mingw-qt5-qtwebkit
mingw-qt5-qtbase
mingw-qt5-qtxmlpatterns
mingw-qt5-qtwinextras
mingw-qt5-qtwebsockets
mingw-qt5-qt3d
mingw-qt5-qttranslations
mingw-qt5-qttools
mingw-qt5-qtsvg
mingw-qt5-qtserialport
mingw-qt5-qtsensors
mingw-qt5-qtscript
mingw-qt5-qtquickcontrols
mingw-qt5-qtmultimedia
mingw-qt5-qtlocation
mingw-qt5-qtimageformats
mingw-qt5-qtgraphicaleffects
mingw-qt5-qtdeclarative
mingw-qt5-qtcharts
mingw-qt5-qtactiveqt
mingw-python-qt5
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
SUSE Linux
Opensuse
Fedora

How to mitigate CVE-2018-19873

Update to version 5.11.3.

Qt - update to 5.11.3
qtbase-opensource-src (Ubuntu package) - addressed in versions 5.5.1+dfsg-16ubuntu7.6, 5.9.5+dfsg-0ubuntu2.1, 5.11.1+dfsg-7ubuntu3.1
qtbase-opensource-src (Debian package) - update to 5.7.1+dfsg-3+deb9u1
qt (Red Hat package) - update to 4.8.7-8.el7
mingw-sip - update to 4.19.13-2.fc29
mingw-qt5-qtwebkit - update to 5.9.4-0.8.gitbd0657f.fc29
mingw-qt5-qtbase - update to 5.11.3-1.fc29
mingw-qt5-qtxmlpatterns - update to 5.11.3-1.fc29
mingw-qt5-qtwinextras - update to 5.11.3-1.fc29
mingw-qt5-qtwebsockets - update to 5.11.3-1.fc29
mingw-qt5-qt3d - update to 5.11.3-1.fc29
mingw-qt5-qttranslations - update to 5.11.3-1.fc29
mingw-qt5-qttools - update to 5.11.3-1.fc29
mingw-qt5-qtsvg - update to 5.11.3-1.fc29
mingw-qt5-qtserialport - update to 5.11.3-1.fc29
mingw-qt5-qtsensors - update to 5.11.3-1.fc29
mingw-qt5-qtscript - update to 5.11.3-1.fc29
mingw-qt5-qtquickcontrols - update to 5.11.3-1.fc29
mingw-qt5-qtmultimedia - update to 5.11.3-1.fc29
mingw-qt5-qtlocation - update to 5.11.3-1.fc29
mingw-qt5-qtimageformats - update to 5.11.3-1.fc29
mingw-qt5-qtgraphicaleffects - update to 5.11.3-1.fc29
mingw-qt5-qtdeclarative - update to 5.11.3-1.fc29
mingw-qt5-qtcharts - update to 5.11.3-1.fc29
mingw-qt5-qtactiveqt - update to 5.11.3-1.fc29
mingw-python-qt5 - update to 5.11.3-2.fc29

External References

Related Security Bulletins