Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-37369

Опубликовано: 20 авг. 2023
Источник: debian
EPSS Низкий

Описание

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qt6-basefixed6.4.2+dfsg-20package
qt6-baseno-dsabookwormpackage
qtbase-opensource-src-glesfixed5.15.10+dfsg-2package
qtbase-opensource-src-glesno-dsabookwormpackage
qtbase-opensource-src-glesno-dsabullseyepackage
qtbase-opensource-srcfixed5.15.10+dfsg-3package
qtbase-opensource-srcfixed5.15.8+dfsg-11+deb12u1bookwormpackage
qtbase-opensource-srcfixed5.15.2+dfsg-9+deb11u1bullseyepackage
qt4-x11removedpackage

Примечания

  • https://www.qt.io/blog/security-advisory-qxmlstreamreader

  • https://codereview.qt-project.org/c/qt/qtbase/+/455027

EPSS

Процентиль: 51%
0.00283
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

CVSS3: 7.5
redhat
почти 2 года назад

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

CVSS3: 7.5
nvd
почти 2 года назад

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

CVSS3: 7.5
msrc
почти 2 года назад

Описание отсутствует

suse-cvrf
больше 1 года назад

Security update for libqt5-qtbase

EPSS

Процентиль: 51%
0.00283
Низкий