FS#64347 - [qt5-webengine] CVE-2019-13720
Attached to Project:
Arch Linux
Opened by Florian Bruhin (The-Compiler) - Friday, 01 November 2019, 16:43 GMT
Last edited by Antonio Rojas (arojas) - Friday, 01 November 2019, 18:34 GMT
Opened by Florian Bruhin (The-Compiler) - Friday, 01 November 2019, 16:43 GMT
Last edited by Antonio Rojas (arojas) - Friday, 01 November 2019, 18:34 GMT
|
Details
https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html
mentions:
[$TBD][1019226] High CVE-2019-13720: Use-after-free in audio. [...] Google is aware of reports that an exploit for CVE-2019-13720 exists in the wild. The patch for 73-based (corresponding to Qt 5.13) is here: https://code.qt.io/cgit/qt/qtwebengine-chromium.git/patch/?id=d6e5fc10e417efdf8665d9fba57c269f0534072f There's also a second use-after-free in PDFium mentioned there, but AFAIK this isn't fixed in QtWebEngine yet (and less critical, as the PDF viewer can be turned off and it's not actively exploited already). |
This task depends upon
Closed by Antonio Rojas (arojas)
Friday, 01 November 2019, 18:34 GMT
Reason for closing: Fixed
Additional comments about closing: qt5-webengine 5.13.2-2
Friday, 01 November 2019, 18:34 GMT
Reason for closing: Fixed
Additional comments about closing: qt5-webengine 5.13.2-2