PT-2018-3709 · Qt Company+7 · Qt+7

CVE-2018-19869

·

Published

2018-07-09

·

Updated

2026-05-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Qt versions prior to 5.11.3
Description The issue is related to a flaw in the input validation mechanism of the qsvghandler.cpp component in the Qt cross-platform framework. This flaw can be exploited by a remote attacker using a malformed SVG image, potentially leading to a denial of service due to a segmentation fault in qsvghandler.cpp.
Recommendations For Qt versions prior to 5.11.3, update to version 5.11.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of SVG images from untrusted sources to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:1665
ALT-PU-2018-2887
ALT-PU-2018-2888
ALT-PU-2018-2889
ALT-PU-2018-2890
ALT-PU-2018-2891
ALT-PU-2018-2892
ALT-PU-2018-2893
ALT-PU-2018-2894
ALT-PU-2018-2895
ALT-PU-2018-2896
ALT-PU-2018-2897
ALT-PU-2018-2898
ALT-PU-2018-2899
ALT-PU-2018-2900
ALT-PU-2018-2901
ALT-PU-2018-2902
ALT-PU-2018-2903
ALT-PU-2018-2904
ALT-PU-2018-2905
ALT-PU-2018-2906
ALT-PU-2018-2907
ALT-PU-2018-2908
ALT-PU-2018-2909
ALT-PU-2018-2910
ALT-PU-2018-2911
ALT-PU-2018-2912
ALT-PU-2018-2913
ALT-PU-2018-2914
ALT-PU-2018-2915
ALT-PU-2018-2916
ALT-PU-2018-2917
ALT-PU-2019-2558
ALT-PU-2019-2583
BDU:2021-03456
CESA-2019_2135
CESA-2020_1172
CESA-2020_1665
CVE-2018-19869
DLA-1786-1
DLA-2377-1
DLA-2422-1
MGASA-2020-0204
OPENSUSE-SU-2019:1116-1
OPENSUSE-SU-2019_1116-1
OPENSUSE-SU-2020:1452-1
OPENSUSE-SU-2020:1500-1
OPENSUSE-SU-2020:1501-1
OPENSUSE-SU-2020:1530-1
OPENSUSE-SU-2020_1452-1
OPENSUSE-SU-2020_1501-1
RHSA-2019:2135
RHSA-2019_2135
RHSA-2020:1172
RHSA-2020:1665
RHSA-2020_1172
RHSA-2020_1665
RLSA-2020:1665
SUSE-SU-2019:0706-1
SUSE-SU-2019_0706-1
SUSE-SU-2020:1021-1
SUSE-SU-2020:2924-1
SUSE-SU-2020_2924-1
USN-5241-1
USN-8337-1

Affected Products

Alt Linux
Almalinux
Centos
Qt
Red Hat
Rocky Linux
Suse
Ubuntu