Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-32762

Опубликовано: 28 мая 2023
Источник: debian

Описание

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qt6-basefixed6.4.2+dfsg-9package
qtbase-opensource-srcfixed5.15.8+dfsg-10package
qtbase-opensource-srcfixed5.15.2+dfsg-9+deb11u1bullseyepackage
qtbase-opensource-src-glesnot-affectedpackage

Примечания

  • https://github.com/qt/qtbase/commit/1b736a815be0222f4b24289cf17575fc15707305

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
nvd
около 2 лет назад

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 5.3
github
около 2 лет назад

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с передачей защищаемой информации в незашифрованном виде, позволяющая нарушителю оказать воздействие на целостность данных