Описание
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| qt6-base | fixed | 6.6.2+dfsg-8 | package | |
| qt6-base | ignored | bookworm | package | |
| qtbase-opensource-src-gles | fixed | 5.15.10+dfsg-3 | package | |
| qtbase-opensource-src-gles | no-dsa | bookworm | package | |
| qtbase-opensource-src-gles | no-dsa | bullseye | package | |
| qtbase-opensource-src | fixed | 5.15.10+dfsg-3 | package | |
| qtbase-opensource-src | fixed | 5.15.8+dfsg-11+deb12u1 | bookworm | package |
| qtbase-opensource-src | fixed | 5.15.2+dfsg-9+deb11u1 | bullseye | package |
| qt4-x11 | removed | package |
Примечания
https://www.qt.io/blog/security-advisory-qxmlstreamreader-1
https://codereview.qt-project.org/c/qt/qtbase/+/488960
https://github.com/qt/qtbase/commit/c4301be7d5f94852e1b17f2c2989d5ca807855d4 (v6.7.0-beta1)
https://github.com/qt/qtbase/commit/b35f5a187d82cdb0c13ef88b506e318f3b793adc (v6.6.0-beta3)
Связанные уязвимости
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15 6.x before 6.2.10 and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.