Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (3)
CVE-2018-19869/qtsvg-opensource-src no-dsa on jessie
· a453a9ad
Emilio Pozuelo Monfort
authored
Dec 13, 2018
a453a9ad
CVE-2018-19871 affects qt4-x11 too
· 1720a0c8
Emilio Pozuelo Monfort
authored
Dec 13, 2018
1720a0c8
CVE-2018-19871 postponed in jessie
· 1323e517
Emilio Pozuelo Monfort
authored
Dec 13, 2018
1323e517
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
1323e517
...
...
@@ -2269,9 +2269,12 @@ CVE-2018-19872
CVE-2018-19871 [QImage: QTgaFile CPU exhaustion]
RESERVED
- qtimageformats-opensource-src <unfixed>
[jessie] - qtimageformats-opensource-src <postponed> (Minor issue)
- qt4-x11 <unfixed>
[jessie] - qt4-x11 <postponed> (Minor issue)
NOTE: https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/
NOTE: https://codereview.qt-project.org/#/c/237761/
TODO: check for completeness, possibly as well qt4-x11
NOTE: qt4-x11 affected in src/plugins/imageformats/tga/qtgafile.cpp
CVE-2018-19870 [Check for QImage allocation failure in qgifhandler]
RESERVED
[experimental] - qtbase-opensource-src 5.11.3+dfsg-1
...
...
@@ -2283,6 +2286,7 @@ CVE-2018-19869 [Fix crash when parsing malformed url reference]
RESERVED
- qtsvg-opensource-src <unfixed> (low)
[stretch] - qtsvg-opensource-src <no-dsa> (Minor issue)
[jessie] - qtsvg-opensource-src <no-dsa> (Minor issue)
NOTE: https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/
NOTE: https://codereview.qt-project.org/#/c/234142/
TODO: check for completeness, possibly as well qt4-x11
data/dla-needed.txt
View file @
1323e517
...
...
@@ -110,9 +110,6 @@ policykit-1 (Santiago)
--
qemu
--
qtsvg-opensource-src
NOTE: 20181210: Needs more investigation around related packages/upstream etc. (lamby)
--
samba (Emilio Pozuelo)
NOTE: 20181203: regression in upstream fix, waiting for confirmed regression fix
--
...
...