Описание
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
qt6-base | fixed | 6.6.2+dfsg-8 | package | |
qt6-base | ignored | bookworm | package | |
qtbase-opensource-src-gles | fixed | 5.15.10+dfsg-3 | package | |
qtbase-opensource-src-gles | no-dsa | bookworm | package | |
qtbase-opensource-src-gles | no-dsa | bullseye | package | |
qtbase-opensource-src | fixed | 5.15.10+dfsg-3 | package | |
qtbase-opensource-src | fixed | 5.15.8+dfsg-11+deb12u1 | bookworm | package |
qtbase-opensource-src | fixed | 5.15.2+dfsg-9+deb11u1 | bullseye | package |
qt4-x11 | removed | package |
Примечания
https://www.qt.io/blog/security-advisory-qxmlstreamreader-1
https://codereview.qt-project.org/c/qt/qtbase/+/488960
https://github.com/qt/qtbase/commit/c4301be7d5f94852e1b17f2c2989d5ca807855d4 (v6.7.0-beta1)
https://github.com/qt/qtbase/commit/b35f5a187d82cdb0c13ef88b506e318f3b793adc (v6.6.0-beta3)
EPSS
Связанные уязвимости
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
Уязвимость функции QXmlStreamReader кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании
EPSS