Qt GUI: Buffer overflow — GLSA 202009-04

Qt GUI has a buffer overflow with unspecified impact.

Affected packages

dev-qt/qtgui on all architectures
Affected versions < 5.14.2-r1
Unaffected versions >= 5.14.2-r1

Background

The GUI module and platform plugins for the Qt5 framework.

Description

It was discovered that Qt GUI’s XBM parser did not properly handle X BitMap files.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Resolution

All Qt GUI users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-qt/qtgui-5.14.2-r1"
 

References

Release date
September 13, 2020

Latest revision
September 13, 2020: 1

Severity
low

Exploitable
local, remote

Bugzilla entries