Debian-LTS alert DLA-210-1 (qt4-x11)
| From: | Raphael Hertzog <hertzog@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 210-1] qt4-x11 security update | |
| Date: | Thu, 30 Apr 2015 13:59:25 +0200 | |
| Message-ID: | <20150430115925.GA31024@home.ouaza.com> |
Package : qt4-x11 Version : 4:4.6.3-4+squeeze3 CVE ID : CVE-2013-0254 CVE-2015-0295 CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 Debian Bug : 779550 783133 This update fixes multiple security issues in the Qt library. CVE-2013-0254 The QSharedMemory class uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server. CVE-2015-0295 / CVE-2015-1858 / CVE-2015-1859 / CVE-2015-1860 Denial of service (via segmentation faults) through crafted images (BMP, GIF, ICO). -- Raphaël Hertzog ◈ Debian Developer Support Debian LTS: http://www.freexian.com/services/debian-lts.html Learn to master Debian: http://debian-handbook.info/get/
