CVE-2019-18281 (https://nvd.nist.gov/vuln/detail/CVE-2019-18281): An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f0f2e0e6f77f988b30bcaeef18e2d4e28708f7b1 commit f0f2e0e6f77f988b30bcaeef18e2d4e28708f7b1 Author: Andreas Sturmlechner <asturm@gentoo.org> AuthorDate: 2020-01-25 23:29:54 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2020-01-25 23:56:18 +0000 dev-qt/qtcore: Fix CVE-2019-18281 Bug: https://bugs.gentoo.org/699226 Package-Manager: Portage-2.3.85, Repoman-2.3.20 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> .../files/qtcore-5.12.3-CVE-2019-18281.patch | 98 ++++++++++++++++++++++ dev-qt/qtcore/qtcore-5.12.3-r1.ebuild | 86 +++++++++++++++++++ 2 files changed, 184 insertions(+)
Arches please stabilise.
x86 stable
arm stable
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c87e6b815222baf8914ae58f8b65122cbfd3f6bf commit c87e6b815222baf8914ae58f8b65122cbfd3f6bf Author: Andreas Sturmlechner <asturm@gentoo.org> AuthorDate: 2020-01-29 20:17:58 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2020-01-29 20:27:58 +0000 dev-qt/qtcore: Security cleanup Bug: https://bugs.gentoo.org/699226 Package-Manager: Portage-2.3.86, Repoman-2.3.20 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> dev-qt/qtcore/qtcore-5.12.3.ebuild | 84 -------------------------------------- 1 file changed, 84 deletions(-)
Tree is clean, thanks all
Added to an existing GLSA.
This issue was resolved and addressed in GLSA 202003-60 at https://security.gentoo.org/glsa/202003-60 by GLSA coordinator Thomas Deutschmann (whissi).