USN-2057-1: Qt vulnerability
17 December 2013
Qt could be made to consume resources and hang if it processed XML data.
Releases
Packages
- qt4-x11 - Qt 4 libraries
- qtbase-opensource-src - Qt 5 libraries
Details
It was discovered that QXmlSimpleReader in Qt incorrectly handled XML
entity expansion. An attacker could use this flaw to cause Qt applications
to consume large amounts of resources, resulting in a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 13.10
Ubuntu 13.04
Ubuntu 12.10
Ubuntu 12.04
After a standard system update you need to restart your session to make all
the necessary changes.