Back to Database
Status published
Medium
CVE-2020-17507
An issue was discovered in Qt through 5.12.9, and 5.13.x...
Vulnerability Description
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-17507
Credits & Attribution
No credits recorded in the NVD database.
References
- https://codereview.qt-project.org/c/qt/qtbase/+/308436
- https://codereview.qt-project.org/c/qt/qtbase/+/308495
- https://codereview.qt-project.org/c/qt/qtbase/+/308496
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/426FCC6JNK4JUEX5QHJQDYQ6MUVQ3E6P/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NBPZVZNEYXGATTXM4WOE7OQ55VAKPVD6/
- https://security.gentoo.org/glsa/202009-04
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00057.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00071.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00090.html
- https://lists.debian.org/debian-lts-announce/2020/09/msg00024.html
- https://lists.debian.org/debian-lts-announce/2020/09/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00104.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00105.html
More from qt
View All →CVE-2022-25634
Qt through 5.15.8 and 6.x through 6.2.3 can load system...
High
7.5
CVE-2022-25255
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before...
High
7.8
CVE-2021-45930
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through...
Medium
5.5
CVE-2021-38593
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an...
High
7.5
CVE-2021-28025
Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1,...
Medium
5.5
Affected Vendor
Affected Software
qt, debian linux, fedora
Vulnerable Versions:
0, 5.13.0, 9.0, 31, 32
Timeline
Official Publish:
August 12th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.