-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: qt security update Advisory ID: RHSA-2020:1172-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1172 Issue date: 2020-03-31 CVE Names: CVE-2018-15518 CVE-2018-19869 CVE-2018-19870 CVE-2018-19871 CVE-2018-19872 CVE-2018-19873 ==================================================================== 1. Summary: An update for qt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 3. Description: The qt packages contain a software toolkit that simplifies the task of writing and maintaining Graphical User Interface (GUI) applications for the X Window System. Security Fix(es): * qt5-qtbase: Double free in QXmlStreamReader (CVE-2018-15518) * qt: Malformed PPM image causing division by zero and crash in qppmhandler.cpp (CVE-2018-19872) * qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service (CVE-2018-19869) * qt5-qtbase: QImage allocation failure in qgifhandler (CVE-2018-19870) * qt5-qtimageformats: QTgaFile CPU exhaustion (CVE-2018-19871) * qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file (CVE-2018-19873) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1658996 - CVE-2018-19870 qt5-qtbase: QImage allocation failure in qgifhandler 1658998 - CVE-2018-19873 qt5-qtbase: QBmpHandler segmentation fault on malformed BMP file 1659000 - CVE-2018-15518 qt5-qtbase: Double free in QXmlStreamReader 1661460 - CVE-2018-19869 qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service 1661465 - CVE-2018-19871 qt5-qtimageformats: QTgaFile CPU exhaustion 1691636 - CVE-2018-19872 qt: Malformed PPM image causing division by zero and crash in qppmhandler.cpp 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: qt-4.8.7-8.el7.src.rpm x86_64: qt-4.8.7-8.el7.i686.rpm qt-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.i686.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-mysql-4.8.7-8.el7.i686.rpm qt-mysql-4.8.7-8.el7.x86_64.rpm qt-x11-4.8.7-8.el7.i686.rpm qt-x11-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: qt-devel-private-4.8.7-8.el7.noarch.rpm qt-doc-4.8.7-8.el7.noarch.rpm x86_64: qt-assistant-4.8.7-8.el7.x86_64.rpm qt-config-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.i686.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-demos-4.8.7-8.el7.x86_64.rpm qt-devel-4.8.7-8.el7.i686.rpm qt-devel-4.8.7-8.el7.x86_64.rpm qt-examples-4.8.7-8.el7.x86_64.rpm qt-odbc-4.8.7-8.el7.i686.rpm qt-odbc-4.8.7-8.el7.x86_64.rpm qt-postgresql-4.8.7-8.el7.i686.rpm qt-postgresql-4.8.7-8.el7.x86_64.rpm qt-qdbusviewer-4.8.7-8.el7.x86_64.rpm qt-qvfb-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: qt-4.8.7-8.el7.src.rpm x86_64: qt-4.8.7-8.el7.i686.rpm qt-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.i686.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-x11-4.8.7-8.el7.i686.rpm qt-x11-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: qt-devel-private-4.8.7-8.el7.noarch.rpm qt-doc-4.8.7-8.el7.noarch.rpm x86_64: qt-assistant-4.8.7-8.el7.x86_64.rpm qt-config-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.i686.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-demos-4.8.7-8.el7.x86_64.rpm qt-devel-4.8.7-8.el7.i686.rpm qt-devel-4.8.7-8.el7.x86_64.rpm qt-examples-4.8.7-8.el7.x86_64.rpm qt-mysql-4.8.7-8.el7.i686.rpm qt-mysql-4.8.7-8.el7.x86_64.rpm qt-odbc-4.8.7-8.el7.i686.rpm qt-odbc-4.8.7-8.el7.x86_64.rpm qt-postgresql-4.8.7-8.el7.i686.rpm qt-postgresql-4.8.7-8.el7.x86_64.rpm qt-qdbusviewer-4.8.7-8.el7.x86_64.rpm qt-qvfb-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: qt-4.8.7-8.el7.src.rpm ppc64: qt-4.8.7-8.el7.ppc.rpm qt-4.8.7-8.el7.ppc64.rpm qt-debuginfo-4.8.7-8.el7.ppc.rpm qt-debuginfo-4.8.7-8.el7.ppc64.rpm qt-devel-4.8.7-8.el7.ppc.rpm qt-devel-4.8.7-8.el7.ppc64.rpm qt-mysql-4.8.7-8.el7.ppc.rpm qt-mysql-4.8.7-8.el7.ppc64.rpm qt-odbc-4.8.7-8.el7.ppc.rpm qt-odbc-4.8.7-8.el7.ppc64.rpm qt-postgresql-4.8.7-8.el7.ppc.rpm qt-postgresql-4.8.7-8.el7.ppc64.rpm qt-x11-4.8.7-8.el7.ppc.rpm qt-x11-4.8.7-8.el7.ppc64.rpm ppc64le: qt-4.8.7-8.el7.ppc64le.rpm qt-debuginfo-4.8.7-8.el7.ppc64le.rpm qt-devel-4.8.7-8.el7.ppc64le.rpm qt-mysql-4.8.7-8.el7.ppc64le.rpm qt-odbc-4.8.7-8.el7.ppc64le.rpm qt-postgresql-4.8.7-8.el7.ppc64le.rpm qt-x11-4.8.7-8.el7.ppc64le.rpm s390x: qt-4.8.7-8.el7.s390.rpm qt-4.8.7-8.el7.s390x.rpm qt-debuginfo-4.8.7-8.el7.s390.rpm qt-debuginfo-4.8.7-8.el7.s390x.rpm qt-devel-4.8.7-8.el7.s390.rpm qt-devel-4.8.7-8.el7.s390x.rpm qt-mysql-4.8.7-8.el7.s390.rpm qt-mysql-4.8.7-8.el7.s390x.rpm qt-odbc-4.8.7-8.el7.s390.rpm qt-odbc-4.8.7-8.el7.s390x.rpm qt-postgresql-4.8.7-8.el7.s390.rpm qt-postgresql-4.8.7-8.el7.s390x.rpm qt-x11-4.8.7-8.el7.s390.rpm qt-x11-4.8.7-8.el7.s390x.rpm x86_64: qt-4.8.7-8.el7.i686.rpm qt-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.i686.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-devel-4.8.7-8.el7.i686.rpm qt-devel-4.8.7-8.el7.x86_64.rpm qt-mysql-4.8.7-8.el7.i686.rpm qt-mysql-4.8.7-8.el7.x86_64.rpm qt-odbc-4.8.7-8.el7.i686.rpm qt-odbc-4.8.7-8.el7.x86_64.rpm qt-postgresql-4.8.7-8.el7.i686.rpm qt-postgresql-4.8.7-8.el7.x86_64.rpm qt-x11-4.8.7-8.el7.i686.rpm qt-x11-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: qt-devel-private-4.8.7-8.el7.noarch.rpm qt-doc-4.8.7-8.el7.noarch.rpm ppc64: qt-assistant-4.8.7-8.el7.ppc64.rpm qt-config-4.8.7-8.el7.ppc64.rpm qt-debuginfo-4.8.7-8.el7.ppc64.rpm qt-demos-4.8.7-8.el7.ppc64.rpm qt-examples-4.8.7-8.el7.ppc64.rpm qt-qdbusviewer-4.8.7-8.el7.ppc64.rpm qt-qvfb-4.8.7-8.el7.ppc64.rpm ppc64le: qt-assistant-4.8.7-8.el7.ppc64le.rpm qt-config-4.8.7-8.el7.ppc64le.rpm qt-debuginfo-4.8.7-8.el7.ppc64le.rpm qt-demos-4.8.7-8.el7.ppc64le.rpm qt-examples-4.8.7-8.el7.ppc64le.rpm qt-qdbusviewer-4.8.7-8.el7.ppc64le.rpm qt-qvfb-4.8.7-8.el7.ppc64le.rpm s390x: qt-assistant-4.8.7-8.el7.s390x.rpm qt-config-4.8.7-8.el7.s390x.rpm qt-debuginfo-4.8.7-8.el7.s390x.rpm qt-demos-4.8.7-8.el7.s390x.rpm qt-examples-4.8.7-8.el7.s390x.rpm qt-qdbusviewer-4.8.7-8.el7.s390x.rpm qt-qvfb-4.8.7-8.el7.s390x.rpm x86_64: qt-assistant-4.8.7-8.el7.x86_64.rpm qt-config-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-demos-4.8.7-8.el7.x86_64.rpm qt-examples-4.8.7-8.el7.x86_64.rpm qt-qdbusviewer-4.8.7-8.el7.x86_64.rpm qt-qvfb-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: qt-4.8.7-8.el7.src.rpm x86_64: qt-4.8.7-8.el7.i686.rpm qt-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.i686.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-devel-4.8.7-8.el7.i686.rpm qt-devel-4.8.7-8.el7.x86_64.rpm qt-mysql-4.8.7-8.el7.i686.rpm qt-mysql-4.8.7-8.el7.x86_64.rpm qt-odbc-4.8.7-8.el7.i686.rpm qt-odbc-4.8.7-8.el7.x86_64.rpm qt-postgresql-4.8.7-8.el7.i686.rpm qt-postgresql-4.8.7-8.el7.x86_64.rpm qt-x11-4.8.7-8.el7.i686.rpm qt-x11-4.8.7-8.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: qt-devel-private-4.8.7-8.el7.noarch.rpm qt-doc-4.8.7-8.el7.noarch.rpm x86_64: qt-assistant-4.8.7-8.el7.x86_64.rpm qt-config-4.8.7-8.el7.x86_64.rpm qt-debuginfo-4.8.7-8.el7.x86_64.rpm qt-demos-4.8.7-8.el7.x86_64.rpm qt-examples-4.8.7-8.el7.x86_64.rpm qt-qdbusviewer-4.8.7-8.el7.x86_64.rpm qt-qvfb-4.8.7-8.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-15518 https://access.redhat.com/security/cve/CVE-2018-19869 https://access.redhat.com/security/cve/CVE-2018-19870 https://access.redhat.com/security/cve/CVE-2018-19871 https://access.redhat.com/security/cve/CVE-2018-19872 https://access.redhat.com/security/cve/CVE-2018-19873 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXoOcU9zjgjWX9erEAQhj8g//VWl5NWlPpuT2rqmXWwBoNPXWabDsruJc IhOwGLjVfWG5XwHl8fdnFfOKw01A3b/iMxX5tKn8RtsQL/qW/FIpfDj0DQyV/kVC Ns6A87/VP/GP0dKhH64/grOV9YZUjbAZYgURAq17AbtE9UCldGebJgH3UJuzKyiT HrwKKeDcolybM9ztK5aBWTIC2WLV9khHC4JXvd4FTkkVvkBeLu2PQkF20Aa1mOwT g0MVIKfciILP0kL3YA2N/ZG8V8wY0fCaQmA9GP6znY1M2jKlXLWGGBvmoLxxA1f9 JXE8o8ox4rAyP9zZ8NXlvxWQ4e7I9fsC+OoFyQKDymmaLGMwqgRP1i4ipJFQki8U rp9mA+s8fa76bofpf6lteF3IRDW+baWkPHJDCUD+NVENfg+FbDFbG3gYc9KwOo7l 5lfYafYwdNb4Vvx5EwPsEUjQSgxNIwTc4ELmoKnxBZBIJz1ZbiqA5hQJCWivZmyG UB2VxQ5XVajCzigHWI46WURPZWuWKLbOkbzZMCWgNeFRyLV8jUZMpSNrDCR1GjYa 1ldrQ5cGSpRy2iwlZwbvTJdOdDYRauhmgUvvooRJCg+9YkpJ9g+S99dEhu6tNJ0Y KFr2ZtPFNewD5mSW9AjAQpoMloJL7WlpjD0HpDTWZTeZa9tVxK3+wr9bBtcPKTPy CGj9a+AJkJg=Hv9d -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce