Digia Qt 缓冲区错误漏洞

admin 2022-10-10 05:05:18 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Digia Qt 缓冲区错误漏洞

  • CNNVD编号:CNNVD-201812-792
  • 危害等级: 超危
  • CVE编号: CVE-2018-19873
  • 漏洞类型: 缓冲区错误
  • 发布时间: 2018-12-19
  • 威胁类型: 远程
  • 更新时间: 2020-09-30
  • 厂        商: opensuse
  • 漏洞来源: Red Hat

漏洞简介

Digia Qt是芬兰Digia公司的一套跨平台的C++应用程序开发框架。该框架可用于开发GUI程序。

Digia Qt 5.11.3之前版本中的QBmpHandler存在缓冲区溢出漏洞。攻击者可借助BMP数据利用该漏洞造成拒绝服务(应用程序崩溃)。

漏洞公告

目前厂商已发布升级补丁以修复漏洞,补丁获取链接:

https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/

参考网址

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/05/msg00014.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00071.HTML

来源:UBUNTU

链接:https://usn.ubuntu.com/4003-1/

来源:CONFIRM

链接:https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00073.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00057.HTML

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2020/09/msg00023.HTML

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2018-12/msg00066.HTML

来源:MLIST

链接:https://lists.debian.org/debian-lts-announce/2019/01/msg00004.HTML

来源:CONFIRM

链接:https://codereview.qt-project.org/#/c/238749/

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:2135

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00090.HTML

来源:REDHAT

链接:https://access.redhat.com/errata/RHSA-2019:3390

来源:DEBIAN

链接:https://www.debian.org/security/2019/dsa-4374

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:2135

来源:usn.ubuntu.com

链接:https://usn.ubuntu.com/4003-1/

来源:access.redhat.com

链接:https://access.redhat.com/errata/RHSA-2019:3390

来源:lists.debian.org

链接:https://lists.debian.org/debian-lts-announce/2019/05/msg00014.HTML

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.2977/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/80850

来源:packetstormsecurity.com

链接:https://packetstormsecurity.com/files/153924/Red-Hat-Security-Advisory-2019-2135-01.HTML

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.4126/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2019.1990/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.1364/

来源:www.auscert.org.au

链接:https://www.auscert.org.au/bulletins/ESB-2020.3340/

受影响实体

  • Opensuse Leap:42.3  

补丁

  • Micro Focus SUSE Linux Enterprise libqt5-qtbase 安全漏洞的修复措施

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
ovmf 缓冲区错误漏洞 CNNVD漏洞

ovmf 缓冲区错误漏洞

漏洞信息详情ovmf 缓冲区错误漏洞CNNVD编号:CNNVD-201812-797危害等级: 中危CVE编号:CVE-2017-5733漏洞类型:缓冲区错误发布时间:2018
评论:0   参与:  0