Vulnerability CVE-2019-18281: Information
Description
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.
Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://bugreports.qt.io/browse/QTBUG-77819 |
|
https://bugs.launchpad.net/ubuntu/+source/qtbase-opensource-src/+bug/1848784 |
|
https://codereview.qt-project.org/c/qt/qtbase/+/271889 |
|
DSA-4556 |
|
20191104 [SECURITY] [DSA 4556-1] qtbase-opensource-src security update |
|
USN-4275-1 | |
GLSA-202003-60 |