Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-9541

Опубликовано: 24 июл. 2015
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

An XML Entity Expansion flaw was found in the QT library. Applications that use QT to load untrusted images, for example, SVG images, or untrusted XML documents, may be vulnerable to this flaw. This flaw allows an attacker to cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5qtOut of support scope
Red Hat Enterprise Linux 5qt4Out of support scope
Red Hat Enterprise Linux 6qtOut of support scope
Red Hat Enterprise Linux 6qt3Out of support scope
Red Hat Enterprise Linux 7qtWill not fix
Red Hat Enterprise Linux 7qt3Not affected
Red Hat Enterprise Linux 8qt5-qtbaseFixedRHSA-2020:469004.11.2020
Red Hat Enterprise Linux 8qt5-qttoolsFixedRHSA-2020:469004.11.2020
Red Hat Enterprise Linux 8qt5-qtwebsocketsFixedRHSA-2020:469004.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=1801369qt: XML entity expansion vulnerability

EPSS

Процентиль: 76%
0.01042
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

CVSS3: 7.5
nvd
больше 5 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

CVSS3: 7.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 5 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via ...

CVSS3: 7.5
github
около 3 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

EPSS

Процентиль: 76%
0.01042
Низкий

7.5 High

CVSS3