CVE-2020-17507: Debian Linux

Medium severity, CVSS 5.3. EPSS: 4% chance of exploitation in the next 30 days.

An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Qt Qt: up to and including 5.12.9; from 5.13.0, before 5.15.1 (fixed in 5.15.1)

Published 2020-08-12. Last modified 2026-06-17.