USN-4003-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-4003-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4003-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4003-1
Related
Published
2019-06-03T15:40:08.328767Z
Modified
2019-06-03T15:40:08.328767Z
Summary
qtbase-opensource-src vulnerabilities
Details

It was discovered that Qt incorrectly handled certain XML documents. A remote attacker could use this issue with a specially crafted XML document to cause Qt to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-15518)

It was discovered that Qt incorrectly handled certain GIF images. A remote attacker could use this issue with a specially crafted GIF image to cause Qt to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-19870)

It was discovered that Qt incorrectly handled certain BMP images. A remote attacker could use this issue with a specially crafted BMP image to cause Qt to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2018-19873)

References

Affected packages

Ubuntu:16.04:LTS / qtbase-opensource-src

Package

Name
qtbase-opensource-src
Purl
pkg:deb/ubuntu/qtbase-opensource-src@5.5.1+dfsg-16ubuntu7.6?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.1+dfsg-16ubuntu7.6

Affected versions

5.*

5.4.2+dfsg-2ubuntu9
5.5.1+dfsg-6ubuntu4
5.5.1+dfsg-10ubuntu2
5.5.1+dfsg-13ubuntu1
5.5.1+dfsg-13ubuntu2
5.5.1+dfsg-13ubuntu3
5.5.1+dfsg-14ubuntu1
5.5.1+dfsg-14ubuntu2
5.5.1+dfsg-14ubuntu3
5.5.1+dfsg-15ubuntu1
5.5.1+dfsg-16ubuntu1
5.5.1+dfsg-16ubuntu6
5.5.1+dfsg-16ubuntu7
5.5.1+dfsg-16ubuntu7.1
5.5.1+dfsg-16ubuntu7.2
5.5.1+dfsg-16ubuntu7.5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "libqt5test5": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5widgets5": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-doc-html": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5dbus5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-odbc": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5concurrent5": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-private-dev-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5network5": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-examples-dbg": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5opengl5-dev": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5xml5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-examples": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-sqlite": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-tds": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5gui5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5widgets5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-mysql-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5opengl5-dev-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5core5a": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-sqlite-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qt5-qmake-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5libqgtk2-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-dev": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5opengl5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-dev-tools": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5printsupport5": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5xml5": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5dbus5": "5.5.1+dfsg-16ubuntu7.6",
            "qt5-qmake-arm-linux-gnueabihf": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-psql-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-private-dev": "5.5.1+dfsg-16ubuntu7.6",
            "qt5-default": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5libqgtk2": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-dev-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5core5a-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qt5-qmake": "5.5.1+dfsg-16ubuntu7.6",
            "qt5-qmake-arm-linux-gnueabihf-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-psql": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-dev-tools-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-examples-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5gui5": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-dbg": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5network5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5opengl5": "5.5.1+dfsg-16ubuntu7.6",
            "qtbase5-dev-tools-dbg": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5printsupport5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5test5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-mysql": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-odbc-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5concurrent5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "qt5-default-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-dbgsym": "5.5.1+dfsg-16ubuntu7.6",
            "libqt5sql5-tds-dbgsym": "5.5.1+dfsg-16ubuntu7.6"
        }
    ]
}

Ubuntu:18.04:LTS / qtbase-opensource-src

Package

Name
qtbase-opensource-src
Purl
pkg:deb/ubuntu/qtbase-opensource-src@5.9.5+dfsg-0ubuntu2.1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.9.5+dfsg-0ubuntu2.1

Affected versions

5.*

5.9.1+dfsg-10ubuntu1
5.9.1+dfsg-10ubuntu2
5.9.2+dfsg-4ubuntu6
5.9.3+dfsg-0ubuntu1
5.9.3+dfsg-0ubuntu3
5.9.3+dfsg-0ubuntu4
5.9.4+dfsg-0ubuntu3
5.9.4+dfsg-0ubuntu4
5.9.5+dfsg-0ubuntu1
5.9.5+dfsg-0ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "libqt5test5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5widgets5": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-doc-html": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5dbus5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-odbc": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5concurrent5": "5.9.5+dfsg-0ubuntu2.1",
            "qt5-gtk-platformtheme-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5network5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5opengl5-dev": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-examples": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5xml5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-sqlite": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-tds": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5gui5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5widgets5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-mysql-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-dev-tools": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5core5a": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-sqlite-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-private-dev": "5.9.5+dfsg-0ubuntu2.1",
            "qt5-default": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-dev": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5opengl5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "qt5-qmake-bin": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5printsupport5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5xml5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5dbus5": "5.9.5+dfsg-0ubuntu2.1",
            "qt5-gtk-platformtheme": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-psql-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5core5a-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-ibase": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-ibase-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-psql": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-doc": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-examples-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "qt5-qmake": "5.9.5+dfsg-0ubuntu2.1",
            "qtbase5-dev-tools-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5gui5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5network5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5printsupport5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-tds-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5opengl5": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5test5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-mysql": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5concurrent5-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "libqt5sql5-odbc-dbgsym": "5.9.5+dfsg-0ubuntu2.1",
            "qt5-qmake-bin-dbgsym": "5.9.5+dfsg-0ubuntu2.1"
        }
    ]
}