Ubuntu alert USN-8337-1 (qtsvg-opensource-src)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8337-1] QtSvg vulnerabilities | |
| Date: | Thu, 28 May 2026 15:57:09 +0000 | |
| Message-ID: | <E1wSd6b-0003XB-Rr@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8337-1 May 28, 2026 qtsvg-opensource-src vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in QtSvg. Software Description: - qtsvg-opensource-src: Qt 5 SVG module Details: It was discovered that QtSvg incorrectly handled certain SVG images. An attacker could possibly use this issue to cause QtSvg to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-19869) It was discovered that QtSvg incorrectly handled certain SVG images. An attacker could use this issue to cause QtSvg to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-3481, CVE-2021-28025, CVE-2021-45930) It was discovered that QtSvg incorrectly handled certain SVG images. An attacker could use this issue to cause QtSvg to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-32573) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libqt5svg5 5.15.3-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libqt5svg5 5.12.8-0ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libqt5svg5 5.9.5-0ubuntu1.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libqt5svg5 5.5.1-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8337-1 CVE-2018-19869, CVE-2021-28025, CVE-2021-3481, CVE-2021-45930, CVE-2023-32573
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoYY5kACgkQcpJm3tlz hgGoaQ/+PlA+ZiYL71jpEfi6PLY4/tkHNnnxaLVhKLku2VlGwMthfd5Bkg30e9cg p7TjstGDZ2O0F2arKiYk1JY33pz116MolmMDPR6nLuDBw9ag7GZ4AQcvgatxna32 Q2u6ImiV+QviRWEeO22oUg8z/ghwhTZUqzGXWr1tkFvFkThtfw0p0ubpeQgndi70 en/gOvDKGhP2kOkT68d1NZ88syQWs485ZWgrMk7GXGvXSGTYsjpvn02B7TZr3eVJ LTFJnvroCNUhwbVvo2+hMROqOsyG4YTswo5r87yFPkHFesI9id72XnwYHfVTiwmp C8+esrQOhKEftc2iJ+sbPXuTOE+epMk6j8lYmC/oceo7zQw+zDeWvmK3MShisoha gdpQPGPfYeSwg29TKaH+aPMrRMCXhpm2vnYJdIn2rJ05rjqpsaxPVs0yQuGizNke JjcUK7k1+wtnfnB49GneVMgx1s1tvKQUF5gbKc+YIkFKya1TkCjfrmxRLf/8X63L VD1InOPSr0TqjwTuBerS8qT6JDhm9dEnfF13IFw7VVd+kPTfkKcjyZ7KEJbz92pY IM+ANy6aUyoQhALFtcb+PSXAsvWH93Mnc7Z0yr/yQUrszImW3Xx8kfGwyfT7bzlk E5NDRsJkMvXyJlBXcEr3gAfKEVgz0tvPdH6vbkFGQnDAqJhPCCo= =0nPd -----END PGP SIGNATURE-----
