|
|
Log in / Subscribe / Register

Arch Linux alert ASA-201911-2 (qt5-webengine)

From:  Morten Linderud <foxboron@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [ASA-201911-2] qt5-webengine: arbitrary code execution
Date:  Sat, 2 Nov 2019 19:50:40 +0100
Message-ID:  <20191102185040.3bcfd3jzxmmj6mxi@anathema>

Arch Linux Security Advisory ASA-201911-2 ========================================= Severity: Critical Date : 2019-11-02 CVE-ID : CVE-2019-13720 Package : qt5-webengine Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-1059 Summary ======= The package qt5-webengine before version 5.13.2-2 is vulnerable to arbitrary code execution. Resolution ========== Upgrade to 5.13.2-2. # pacman -Syu "qt5-webengine>=5.13.2-2" The problem has been fixed upstream but no release is available yet. Workaround ========== None. Description =========== A use-after-free vulnerability has been found in the audio component of the chromium browser before 78.0.3904.87. Google is aware of reports that an exploit for this vulnerability exists in the wild. Impact ====== A remote attacker can execute arbitrary code on the affected host. References ========== https://bugs.archlinux.org/task/64347 https://code.qt.io/cgit/qt/qtwebengine-chromium.git/patch... https://chromereleases.googleblog.com/2019/10/stable-chan... https://crbug.com/1019226 https://security.archlinux.org/CVE-2019-13720


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds