Описание
Security update for libqt5-qtbase
This update for libqt5-qtbase fixes the following issues:
- CVE-2023-34410: Fixed certificate validation does not always consider whether the root of a chain is a configured CA certificate (bsc#1211994).
- CVE-2023-33285: Fixed buffer overflow in QDnsLookup (bsc#1211642).
- CVE-2023-32762: Fixed Qt Network incorrectly parses the strict-transport-security (HSTS) header (bsc#1211797).
- CVE-2023-38197: Fixed infinite loops in QXmlStreamReader(bsc#1213326).
- CVE-2023-24607: Fixed Qt SQL ODBC driver plugin DOS (bsc#1209616).
Список пакетов
Image SLES15-SP2-SAP-Azure
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
Image SLES15-SP2-SAP-BYOS-Azure
Image SLES15-SP2-SAP-BYOS-EC2-HVM
Image SLES15-SP2-SAP-BYOS-GCE
Image SLES15-SP2-SAP-EC2-HVM
Image SLES15-SP2-SAP-GCE
Image SLES15-SP3-SAP-BYOS-Azure
Image SLES15-SP3-SAP-BYOS-EC2-HVM
Image SLES15-SP3-SAP-BYOS-GCE
SUSE Enterprise Storage 7
SUSE Enterprise Storage 7.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
SUSE Linux Enterprise Server 15 SP2-LTSS
SUSE Linux Enterprise Server 15 SP3-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
Ссылки
- Link for SUSE-SU-2023:3207-1
- E-Mail link for SUSE-SU-2023:3207-1
- SUSE Security Ratings
- SUSE Bug 1209616
- SUSE Bug 1211642
- SUSE Bug 1211797
- SUSE Bug 1211994
- SUSE Bug 1213326
- SUSE CVE CVE-2023-24607 page
- SUSE CVE CVE-2023-32762 page
- SUSE CVE CVE-2023-33285 page
- SUSE CVE CVE-2023-34410 page
- SUSE CVE CVE-2023-38197 page
Описание
Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.
Затронутые продукты
Ссылки
- CVE-2023-24607
- SUSE Bug 1209616
Описание
An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
Затронутые продукты
Ссылки
- CVE-2023-32762
- SUSE Bug 1211797
Описание
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
Затронутые продукты
Ссылки
- CVE-2023-33285
- SUSE Bug 1211642
Описание
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
Затронутые продукты
Ссылки
- CVE-2023-34410
- SUSE Bug 1211994
Описание
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
Затронутые продукты
Ссылки
- CVE-2023-38197
- SUSE Bug 1213326