{"id":"RLSA-2020:1665","summary":"Moderate: qt5 security, bug fix, and enhancement update","details":"Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.\n\nThe following packages have been upgraded to a later upstream version: qt5 (5.12.5), qt5-qt3d (5.12.5), qt5-qtbase (5.12.5), qt5-qtcanvas3d (5.12.5), qt5-qtconnectivity (5.12.5), qt5-qtdeclarative (5.12.5), qt5-qtdoc (5.12.5), qt5-qtgraphicaleffects (5.12.5), qt5-qtimageformats (5.12.5), qt5-qtlocation (5.12.5), qt5-qtmultimedia (5.12.5), qt5-qtquickcontrols (5.12.5), qt5-qtquickcontrols2 (5.12.5), qt5-qtscript (5.12.5), qt5-qtsensors (5.12.5), qt5-qtserialbus (5.12.5), qt5-qtserialport (5.12.5), qt5-qtsvg (5.12.5), qt5-qttools (5.12.5), qt5-qttranslations (5.12.5), qt5-qtwayland (5.12.5), qt5-qtwebchannel (5.12.5), qt5-qtwebsockets (5.12.5), qt5-qtx11extras (5.12.5), qt5-qtxmlpatterns (5.12.5), python-qt5 (5.13.1), sip (4.19.19). (BZ#1775603, BZ#1775604)\n\nSecurity Fix(es):\n\n* qt: Malformed PPM image causing division by zero and crash in qppmhandler.cpp (CVE-2018-19872)\n\n* qt5-qtsvg: Invalid parsing of malformed url reference resulting in a denial of service (CVE-2018-19869)\n\n* qt5-qtimageformats: QTgaFile CPU exhaustion (CVE-2018-19871)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.2 Release Notes linked from the References section.","modified":"2026-02-04T21:15:06.795246Z","published":"2020-04-28T09:02:52Z","upstream":["CVE-2018-19869","CVE-2018-19871","CVE-2018-19872","CVE-2019-18281"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2020:1665"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733150"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1661460"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1661465"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1691636"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733133"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733134"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733135"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733136"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733137"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733139"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733140"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733141"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733142"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733143"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733144"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733145"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733146"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733147"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733148"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733149"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733151"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733152"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733153"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733154"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733155"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733156"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733157"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733158"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1733159"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1765637"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1769077"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1774418"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1775603"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1775604"}],"affected":[{"package":{"name":"python-qt5","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/python-qt5?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.13.1-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qgnomeplatform","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qgnomeplatform?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:0.4-3.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-3.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qt3d","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qt3d?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-2.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtcanvas3d","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtcanvas3d?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtconnectivity","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtconnectivity?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtdeclarative","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtdeclarative?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtdoc","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtdoc?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtgraphicaleffects","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtgraphicaleffects?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtimageformats","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtimageformats?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtlocation","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtlocation?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtmultimedia","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtmultimedia?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtquickcontrols2","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtquickcontrols2?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtquickcontrols","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtquickcontrols?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtscript","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtscript?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtsensors","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtsensors?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtserialbus","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtserialbus?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtserialport","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtserialport?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtsvg","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtsvg?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qttranslations","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qttranslations?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtwayland","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtwayland?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtwebchannel","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtwebchannel?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtx11extras","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtx11extras?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}},{"package":{"name":"qt5-qtxmlpatterns","ecosystem":"Rocky Linux:8","purl":"pkg:rpm/rocky-linux/qt5-qtxmlpatterns?distro=rocky-linux-8-4-legacy&epoch=0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:5.12.5-1.el8"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2020:1665.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}