[ubuntu/bionic-updates] qtbase-opensource-src 5.9.5+dfsg-0ubuntu2.5 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Mon Feb 10 13:58:53 UTC 2020


qtbase-opensource-src (5.9.5+dfsg-0ubuntu2.5) bionic-security; urgency=medium

  * SECURITY UPDATE: division-by-zero via malformed PPM image
    - debian/patches/CVE-2018-19872.patch: add extra check to
      src/gui/image/qppmhandler.cpp.
    - CVE-2018-19872
  * SECURITY UPDATE: QPluginLoader loads plugins from the CWD
    - debian/patches/CVE-2020-0569.patch: do not load plugin from the $PWD
      in src/corelib/plugin/qpluginloader.cpp.
    - CVE-2020-0569

Date: 2020-02-07 20:06:23.121743+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.9.5+dfsg-0ubuntu2.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list