Oval Definition:oval:com.redhat.rhsa:def:20201172
Revision Date:2020-03-31Version:637
Title:RHSA-2020:1172: qt security update (Moderate)
Description:The qt packages contain a software toolkit that simplifies the task of writing and maintaining Graphical User Interface (GUI) applications for the X Window System.

Security Fix(es):

  • qt5-qtbase: Double free in QXmlStreamReader (CVE-2018-15518)

  • qt: Malformed PPM image causing division by zero and crash in qppmhandler.cpp (CVE-2018-19872)

  • qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service (CVE-2018-19869)

  • qt5-qtbase: QImage allocation failure in qgifhandler (CVE-2018-19870)

  • qt5-qtimageformats: QTgaFile CPU exhaustion (CVE-2018-19871)

  • qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file (CVE-2018-19873)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-15518
    CVE-2018-19869
    CVE-2018-19870
    CVE-2018-19871
    CVE-2018-19872
    CVE-2018-19873
    RHSA-2020:1172
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • qt is earlier than 1:4.8.7-8.el7
  • AND qt is signed with Red Hat redhatrelease2 key
  • qt-assistant is earlier than 1:4.8.7-8.el7
  • AND qt-assistant is signed with Red Hat redhatrelease2 key
  • qt-config is earlier than 1:4.8.7-8.el7
  • AND qt-config is signed with Red Hat redhatrelease2 key
  • qt-demos is earlier than 1:4.8.7-8.el7
  • AND qt-demos is signed with Red Hat redhatrelease2 key
  • qt-devel is earlier than 1:4.8.7-8.el7
  • AND qt-devel is signed with Red Hat redhatrelease2 key
  • qt-devel-private is earlier than 1:4.8.7-8.el7
  • AND qt-devel-private is signed with Red Hat redhatrelease2 key
  • qt-doc is earlier than 1:4.8.7-8.el7
  • AND qt-doc is signed with Red Hat redhatrelease2 key
  • qt-examples is earlier than 1:4.8.7-8.el7
  • AND qt-examples is signed with Red Hat redhatrelease2 key
  • qt-mysql is earlier than 1:4.8.7-8.el7
  • AND qt-mysql is signed with Red Hat redhatrelease2 key
  • qt-odbc is earlier than 1:4.8.7-8.el7
  • AND qt-odbc is signed with Red Hat redhatrelease2 key
  • qt-postgresql is earlier than 1:4.8.7-8.el7
  • AND qt-postgresql is signed with Red Hat redhatrelease2 key
  • qt-qdbusviewer is earlier than 1:4.8.7-8.el7
  • AND qt-qdbusviewer is signed with Red Hat redhatrelease2 key
  • qt-qvfb is earlier than 1:4.8.7-8.el7
  • AND qt-qvfb is signed with Red Hat redhatrelease2 key
  • qt-x11 is earlier than 1:4.8.7-8.el7
  • AND qt-x11 is signed with Red Hat redhatrelease2 key
  • BACK