Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-38197

Опубликовано: 13 июл. 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qt6-basefixed6.6.2+dfsg-8package
qt6-baseignoredbookwormpackage
qtbase-opensource-src-glesfixed5.15.10+dfsg-3package
qtbase-opensource-src-glesno-dsabookwormpackage
qtbase-opensource-src-glesno-dsabullseyepackage
qtbase-opensource-srcfixed5.15.10+dfsg-3package
qtbase-opensource-srcfixed5.15.8+dfsg-11+deb12u1bookwormpackage
qtbase-opensource-srcfixed5.15.2+dfsg-9+deb11u1bullseyepackage
qt4-x11removedpackage

Примечания

  • https://www.qt.io/blog/security-advisory-qxmlstreamreader-1

  • https://codereview.qt-project.org/c/qt/qtbase/+/488960

  • https://github.com/qt/qtbase/commit/c4301be7d5f94852e1b17f2c2989d5ca807855d4 (v6.7.0-beta1)

  • https://github.com/qt/qtbase/commit/b35f5a187d82cdb0c13ef88b506e318f3b793adc (v6.6.0-beta3)

EPSS

Процентиль: 13%
0.00044
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

CVSS3: 7.5
redhat
почти 2 года назад

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

CVSS3: 7.5
nvd
почти 2 года назад

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

CVSS3: 7.5
github
почти 2 года назад

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость функции QXmlStreamReader кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 13%
0.00044
Низкий