Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
{
"binaries": [
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5concurrent5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5core5a"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5dbus5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5gui5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5network5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5opengl5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5opengl5-dev"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5printsupport5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5-ibase"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5-mysql"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5-odbc"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5-psql"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5-sqlite"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5sql5-tds"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5test5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5widgets5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "libqt5xml5"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qt5-default"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qt5-flatpak-platformtheme"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qt5-gtk-platformtheme"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qt5-qmake"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qt5-qmake-bin"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qt5-xdgdesktopportal-platformtheme"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qtbase5-dev"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qtbase5-dev-tools"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qtbase5-doc-dev"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qtbase5-doc-html"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qtbase5-examples"
},
{
"binary_version": "5.12.8+dfsg-0ubuntu2.1+esm1",
"binary_name": "qtbase5-private-dev"
}
]
}