Ubuntu Multiple Vulnerabilities in LibTIFF Affect QT WebEngine, Texmaker, and GDAL
Article Content
- •QT WebEngine, Texmaker, and GDAL are vulnerable due to issues in the vendored LibTIFF.
- •Attackers can exploit these vulnerabilities to cause denial of service or execute arbitrary code.
- •Users should update their systems to the latest package versions to mitigate risks.
Recent vulnerabilities have been discovered in QT WebEngine, Texmaker, and GDAL, all stemming from the vendored LibTIFF. These vulnerabilities allow attackers to potentially crash the applications, execute arbitrary code, or obtain sensitive information through specially crafted TIFF image metadata. The issues are classified as denial of service vulnerabilities, affecting users of these applications across various systems. Affected users are advised to update their systems to mitigate the risks associated with these vulnerabilities. The vulnerabilities were disclosed on May 28, 2026, and are part of a broader security advisory from Ubuntu. Users are encouraged to apply standard system updates to ensure protection. No specific CVEs have been mentioned in the articles.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…