qt5-qtbase: Out-of-bounds access in generateDirectionalRuns() function in qtextengine.cpp
Published Oct 23, 2019
4.3
MEDIUMCVSS 3.1
EPSS 2.05%
Description
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.
Affected products
No data.
Configuration 1
Configuration 2
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 8
python-qt5-0:5.13.1-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qgnomeplatform-0:0.4-3.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-0:5.12.5-3.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qt3d-0:5.12.5-2.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtbase-0:5.12.5-4.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtcanvas3d-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtconnectivity-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtdeclarative-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtdoc-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtgraphicaleffects-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtimageformats-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtlocation-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtmultimedia-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtquickcontrols-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtquickcontrols2-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtscript-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtsensors-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtserialbus-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtserialport-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtsvg-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qttools-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qttranslations-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtwayland-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtwebchannel-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtwebsockets-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtx11extras-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
qt5-qtxmlpatterns-0:5.12.5-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 8
sip-0:4.19.19-1.el8
Fixed · RHSA-2020:1665
Red Hat Enterprise Linux 7
qt5-qtbase
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python-qt5-0:5.13.1-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qgnomeplatform-0:0.4-3.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-0:5.12.5-3.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qt3d-0:5.12.5-2.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtbase-0:5.12.5-4.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtcanvas3d-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtconnectivity-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtdeclarative-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtdoc-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtgraphicaleffects-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtimageformats-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtlocation-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtmultimedia-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtquickcontrols-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtquickcontrols2-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtscript-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtsensors-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtserialbus-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtserialport-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtsvg-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qttools-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qttranslations-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtwayland-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtwebchannel-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtwebsockets-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtx11extras-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | qt5-qtxmlpatterns-0:5.12.5-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 8 | sip-0:4.19.19-1.el8 | Fixed | RHSA-2020:1665 |
| Red Hat Enterprise Linux 7 | qt5-qtbase | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 7 is not affected by this issue as qt5-base version as shipped with it doesn't have the code which contains the bug.
References (12)
- https://access.redhat.com/security/cve/CVE-2019-18281 Vendor Advisory
- https://bugreports.qt.io/browse/QTBUG-77819 x_refsource_MISCPermissions Required
- https://bugs.launchpad.net/ubuntu/+source/qtbase-opensource-src/+bug/1848784 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1764742 Issue Tracking
- https://codereview.qt-project.org/c/qt/qtbase/+/271889 x_refsource_MISCPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8070 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-18281
- https://seclists.org/bugtraq/2019/Nov/4 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-60 vendor-advisoryx_refsource_GENTOO
- https://usn.ubuntu.com/4275-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-18281
- https://www.debian.org/security/2019/dsa-4556 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-18281 | Vendor Advisory | |
| https://bugreports.qt.io/browse/QTBUG-77819 | x_refsource_MISCPermissions Required | |
| https://bugs.launchpad.net/ubuntu/+source/qtbase-opensource-src/+bug/1848784 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1764742 | Issue Tracking | |
| https://codereview.qt-project.org/c/qt/qtbase/+/271889 | x_refsource_MISCPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-8070 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-18281 | ||
| https://seclists.org/bugtraq/2019/Nov/4 | mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory | |
| https://security.gentoo.org/glsa/202003-60 | vendor-advisoryx_refsource_GENTOO | |
| https://usn.ubuntu.com/4275-1/ | vendor-advisoryx_refsource_UBUNTU | |
| https://www.cve.org/CVERecord?id=CVE-2019-18281 | ||
| https://www.debian.org/security/2019/dsa-4556 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.