Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-4623

Опубликовано: 18 июл. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-4623: qt5-qtbase security update (IMPORTANT)

[5.15.9-10]

  • HTTP2: Delay any communication until encrypted() can be responded to Resolves: RHEL-46348

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

qt5-qtbase

5.15.9-10.el9_4

qt5-qtbase-common

5.15.9-10.el9_4

qt5-qtbase-devel

5.15.9-10.el9_4

qt5-qtbase-examples

5.15.9-10.el9_4

qt5-qtbase-gui

5.15.9-10.el9_4

qt5-qtbase-mysql

5.15.9-10.el9_4

qt5-qtbase-odbc

5.15.9-10.el9_4

qt5-qtbase-postgresql

5.15.9-10.el9_4

qt5-qtbase-private-devel

5.15.9-10.el9_4

qt5-qtbase-static

5.15.9-10.el9_4

Oracle Linux x86_64

qt5-qtbase

5.15.9-10.el9_4

qt5-qtbase-common

5.15.9-10.el9_4

qt5-qtbase-devel

5.15.9-10.el9_4

qt5-qtbase-examples

5.15.9-10.el9_4

qt5-qtbase-gui

5.15.9-10.el9_4

qt5-qtbase-mysql

5.15.9-10.el9_4

qt5-qtbase-odbc

5.15.9-10.el9_4

qt5-qtbase-postgresql

5.15.9-10.el9_4

qt5-qtbase-private-devel

5.15.9-10.el9_4

qt5-qtbase-static

5.15.9-10.el9_4

Связанные CVE

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 7.5
redhat
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 8.6
nvd
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 5.9
msrc
около 1 года назад

Описание отсутствует

CVSS3: 8.6
debian
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2. ...