File _patchinfo of Package patchinfo.35255
<patchinfo incident="35255">
<issue tracker="bnc" id="1228204">VUL-0: CVE-2024-40724: libqt5-qt3d: assimp: heap-based buffer overflow in the PLY importer class</issue>
<issue tracker="cve" id="2024-40724"/>
<packager>alarrosa</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for libqt5-qt3d</summary>
<description>This update for libqt5-qt3d fixes the following issues:
- CVE-2024-40724: Fixed heap-based buffer overflow in the PLY importer class in assimp (bsc#1228204)
Other fixes:
- Check for a nullptr returned from the shader manager
- Fill image with transparency by default to avoid having junk if it's not filled properly before the first paint call
- Fix QTextureAtlas parenting that could lead to crashes due to being used after free'd.
</description>
</patchinfo>