An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.
| Software | From | Fixed in |
|---|---|---|
| qt / qtbase | 5.11.0 | 5.11.3.x |
| qt / qtbase | 5.12.0 | 5.12.5 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |