MGASA-2019-0356

Source
https://advisories.mageia.org/MGASA-2019-0356.html
Import Source
https://advisories.mageia.org/MGASA-2019-0356.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0356
Related
Published
2019-12-06T14:15:42Z
Modified
2019-12-24T11:54:50Z
Summary
Updated QT stack fix security vulnerability
Details

This update provides the 5.12.6 QT stack maintenance release and fixes the following security issue:

An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters (CVE-2019-18281).

kwin and skrooge has been rebuilt to pick up proper dependencies on the updated QT packages.

References
Credits

Affected packages