QID 198637

Date Published: 2022-01-24

QID 198637: Ubuntu Security Notification for QtSvg Vulnerabilities (USN-5241-1)

Qtsvg incorrectly handled certain malformed svgimages.

If a user or automated system were tricked into opening a speciallycrafted image file, a remote attacker could use this issue to cause qtsvgto crash, resulting in a denial of service, or possibly execute arbitrarycode.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5241-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198637

    Software Advisories
    Advisory ID Software Component Link
    USN-5241-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5241-1