Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:4690

Опубликовано: 03 нояб. 2020
Источник: rocky
Оценка: Moderate

Описание

Moderate: qt5-qtbase and qt5-qtwebsockets security and bug fix update

Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.

Security Fix(es):

  • qt: XML entity expansion vulnerability (CVE-2015-9541)

  • qt5-qtwebsockets: websocket implementation allows only limited size for frames and messages therefore attacker can cause DOS (CVE-2018-21035)

  • qt: files placed by attacker can influence the working directory and lead to malicious code execution (CVE-2020-0569)

  • qt: files placed by attacker can influence the working directory and lead to malicious code execution (CVE-2020-0570)

  • qt5: incorrectly calls SSL_shutdown() in OpenSSL mid-handshake causing denial of service in TLS applications (CVE-2020-13962)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
qt5-qtwebsocketsi6862.el8qt5-qtwebsockets-5.12.5-2.el8.i686.rpm
qt5-qtwebsocketsx86_642.el8qt5-qtwebsockets-5.12.5-2.el8.x86_64.rpm
qt5-qtwebsockets-develi6862.el8qt5-qtwebsockets-devel-5.12.5-2.el8.i686.rpm
qt5-qtwebsockets-develx86_642.el8qt5-qtwebsockets-devel-5.12.5-2.el8.x86_64.rpm
qt5-qtwebsockets-examplesx86_642.el8qt5-qtwebsockets-examples-5.12.5-2.el8.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 5 лет назад

ELSA-2020-4690: qt5-qtbase and qt5-qtwebsockets security and bug fix update (MODERATE)

CVSS3: 7.5
ubuntu
почти 6 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

CVSS3: 7.5
redhat
больше 10 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

CVSS3: 7.5
nvd
почти 6 лет назад

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует