CVE Vulnerabilities

CVE-2018-19865

Insertion of Sensitive Information into Log File

Published: Dec 05, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Qt Qt 5.7.0 (including) 5.7.1 (including)
Qt Qt 5.9.0 (including) 5.9.7 (including)
Qt Qt 5.10.0 (including) 5.10.1 (including)
Qt Qt 5.11.0 (including) 5.11.3 (excluding)
Qt Qt 5.8.0 (including) 5.8.0 (including)
Qtvirtualkeyboard-opensource-src Ubuntu bionic *
Qtvirtualkeyboard-opensource-src Ubuntu cosmic *
Qtvirtualkeyboard-opensource-src Ubuntu disco *
Qtvirtualkeyboard-opensource-src Ubuntu eoan *
Qtvirtualkeyboard-opensource-src Ubuntu focal *
Qtvirtualkeyboard-opensource-src Ubuntu groovy *
Qtvirtualkeyboard-opensource-src Ubuntu hirsute *
Qtvirtualkeyboard-opensource-src Ubuntu impish *
Qtvirtualkeyboard-opensource-src Ubuntu kinetic *
Qtvirtualkeyboard-opensource-src Ubuntu lunar *
Qtvirtualkeyboard-opensource-src Ubuntu mantic *
Qtvirtualkeyboard-opensource-src Ubuntu oracular *

Potential Mitigations

References