Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 699226 (CVE-2019-18281) - <dev-qt/qtcore-5.13.2: Out-of-bounds access in generateDirectionalRuns() function in qtextengine.cpp (CVE-2019-18281)
Summary: <dev-qt/qtcore-5.13.2: Out-of-bounds access in generateDirectionalRuns() func...
Status: RESOLVED FIXED
Alias: CVE-2019-18281
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on: qt-5.12.5-stable
Blocks:
  Show dependency tree
 
Reported: 2019-11-03 13:07 UTC by GLSAMaker/CVETool Bot
Modified: 2020-03-26 18:53 UTC (History)
1 user (show)

See Also:
Package list:
dev-qt/qtcore-5.12.3-r1
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2019-11-03 13:07:36 UTC
CVE-2019-18281 (https://nvd.nist.gov/vuln/detail/CVE-2019-18281):
  An out-of-bounds memory access in the generateDirectionalRuns() function in
  qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows
  attackers to cause a denial of service by crashing an application via a text
  file containing many directional characters.
Comment 1 Larry the Git Cow gentoo-dev 2020-01-25 23:56:45 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f0f2e0e6f77f988b30bcaeef18e2d4e28708f7b1

commit f0f2e0e6f77f988b30bcaeef18e2d4e28708f7b1
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2020-01-25 23:29:54 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2020-01-25 23:56:18 +0000

    dev-qt/qtcore: Fix CVE-2019-18281
    
    Bug: https://bugs.gentoo.org/699226
    Package-Manager: Portage-2.3.85, Repoman-2.3.20
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 .../files/qtcore-5.12.3-CVE-2019-18281.patch       | 98 ++++++++++++++++++++++
 dev-qt/qtcore/qtcore-5.12.3-r1.ebuild              | 86 +++++++++++++++++++
 2 files changed, 184 insertions(+)
Comment 2 Andreas Sturmlechner gentoo-dev 2020-01-25 23:58:08 UTC
Arches please stabilise.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2020-01-26 20:57:35 UTC
x86 stable
Comment 4 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2020-01-27 11:33:30 UTC
arm stable
Comment 5 Larry the Git Cow gentoo-dev 2020-01-29 20:28:24 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c87e6b815222baf8914ae58f8b65122cbfd3f6bf

commit c87e6b815222baf8914ae58f8b65122cbfd3f6bf
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2020-01-29 20:17:58 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2020-01-29 20:27:58 +0000

    dev-qt/qtcore: Security cleanup
    
    Bug: https://bugs.gentoo.org/699226
    Package-Manager: Portage-2.3.86, Repoman-2.3.20
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 dev-qt/qtcore/qtcore-5.12.3.ebuild | 84 --------------------------------------
 1 file changed, 84 deletions(-)
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-03-19 01:11:55 UTC
Tree is clean, thanks all
Comment 7 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-26 18:43:52 UTC
Added to an existing GLSA.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2020-03-26 18:53:14 UTC
This issue was resolved and addressed in
 GLSA 202003-60 at https://security.gentoo.org/glsa/202003-60
by GLSA coordinator Thomas Deutschmann (whissi).