Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.883358
Category:CentOS Local Security Checks
Title:CentOS: Security Advisory for qt5-qtimageformats (CESA-2021:2328)
Summary:The remote host is missing an update for the 'qt5-qtimageformats'; package(s) announced via the CESA-2021:2328 advisory.
Description:Summary:
The remote host is missing an update for the 'qt5-qtimageformats'
package(s) announced via the CESA-2021:2328 advisory.

Vulnerability Insight:
The Qt Image Formats in an add-on module for the core Qt Gui library that
provides support for additional image formats including MNG, TGA, TIFF,
WBMP, and WebP.

Security Fix(es):

* libwebp: heap-based buffer overflow in PutLE16() (CVE-2018-25011)

* libwebp: use of uninitialized value in ReadSymbol() (CVE-2018-25014)

* libwebp: heap-based buffer overflow in WebPDecode*Into functions
(CVE-2020-36328)

* libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c
(CVE-2020-36329)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'qt5-qtimageformats' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-25011
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9119
https://bugzilla.redhat.com/show_bug.cgi?id=1956919
https://chromium.googlesource.com/webm/libwebp/+/v1.0.1
https://chromium.googlesource.com/webm/libwebp/+log/be738c6d396fa5a272c1b209be4379a7532debfe..29fb8562c60b5a919a75d904ff7366af423f8ab9?pretty=fuller&n=10000
Common Vulnerability Exposure (CVE) ID: CVE-2018-25014
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9496
https://bugzilla.redhat.com/show_bug.cgi?id=1956927
https://chromium.googlesource.com/webm/libwebp/+log/78ad57a36ad69a9c22874b182d49d64125c380f2..907208f97ead639bd52
Common Vulnerability Exposure (CVE) ID: CVE-2020-36328
Debian Security Information: DSA-4930 (Google Search)
https://www.debian.org/security/2021/dsa-4930
http://seclists.org/fulldisclosure/2021/Jul/54
https://bugzilla.redhat.com/show_bug.cgi?id=1956829
https://lists.debian.org/debian-lts-announce/2021/06/msg00005.html
https://lists.debian.org/debian-lts-announce/2021/06/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-36329
https://bugzilla.redhat.com/show_bug.cgi?id=1956843
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.