MGASA-2021-0493 - Updated qtbase5 packages fix security vulnerability

Publication date: 27 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0493.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-38593,
     CVE-2020-17507

It was discovered that Qt incorrectly handled certain XBM image files. If a
user or automated system were tricked into opening a specially crafted PPM
file, a remote attacker could cause Qt to crash, resulting in a denial of
service. (CVE-2020-17507)

It was discovered that Qt incorrectly handled certain graphics operations.
If a user or automated system were tricked into performing certain graphics
operations, a remote attacker could cause Qt to crash, resulting in a
denial of service. (CVE-2021-38593)

References:
- https://bugs.mageia.org/show_bug.cgi?id=29468
- https://ubuntu.com/security/notices/USN-5081-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38593
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17507

SRPMS:
- 8/core/qtbase5-5.15.2-4.4.mga8

Mageia 2021-0493: qtbase5 security update

It was discovered that Qt incorrectly handled certain XBM image files

Summary

It was discovered that Qt incorrectly handled certain XBM image files. If a user or automated system were tricked into opening a specially crafted PPM file, a remote attacker could cause Qt to crash, resulting in a denial of service. (CVE-2020-17507)
It was discovered that Qt incorrectly handled certain graphics operations. If a user or automated system were tricked into performing certain graphics operations, a remote attacker could cause Qt to crash, resulting in a denial of service. (CVE-2021-38593)

References

- https://bugs.mageia.org/show_bug.cgi?id=29468

- https://ubuntu.com/security/notices/USN-5081-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38593

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17507

Resolution

MGASA-2021-0493 - Updated qtbase5 packages fix security vulnerability

SRPMS

- 8/core/qtbase5-5.15.2-4.4.mga8

Severity
Publication date: 27 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0493.html
Type: security
CVE: CVE-2021-38593, CVE-2020-17507

Related News