Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:3380-1

Опубликовано: 22 авг. 2023
Источник: suse-cvrf

Описание

Security update for qt6-base

This update for qt6-base fixes the following issues:

  • CVE-2023-34410: Fixed certificate validation flaw (bsc#1211994).
  • CVE-2023-33285: Fixed buffer overflow in QDnsLookup (bsc#1211642).
  • CVE-2023-32762: Fixed strict-transport-security (HSTS) header parsing error (QTBUG-113392) (bsc#1211797).
  • CVE-2023-38197: Fixed infinite loops in QXmlStreamReader (QTBUG-92113, QTBUG-95188) (bsc#1213326).
  • CVE-2023-32763: Fixed buffer overflow in QTextLayout (QTBUG-113337, QTBUG-106947, QTBUG-89557, QTBUG-104986) (bsc#1211798).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP4
libQt6Concurrent6-6.2.2-150400.4.6.1
libQt6Core6-6.2.2-150400.4.6.1
libQt6DBus6-6.2.2-150400.4.6.1
libQt6Gui6-6.2.2-150400.4.6.1
libQt6Network6-6.2.2-150400.4.6.1
libQt6OpenGL6-6.2.2-150400.4.6.1
libQt6OpenGLWidgets6-6.2.2-150400.4.6.1
libQt6PrintSupport6-6.2.2-150400.4.6.1
libQt6Sql6-6.2.2-150400.4.6.1
libQt6Test6-6.2.2-150400.4.6.1
libQt6Widgets6-6.2.2-150400.4.6.1
libQt6Xml6-6.2.2-150400.4.6.1
qt6-base-common-devel-6.2.2-150400.4.6.1
qt6-base-devel-6.2.2-150400.4.6.1
qt6-concurrent-devel-6.2.2-150400.4.6.1
qt6-core-devel-6.2.2-150400.4.6.1
qt6-core-private-devel-6.2.2-150400.4.6.1
qt6-dbus-devel-6.2.2-150400.4.6.1
qt6-gui-devel-6.2.2-150400.4.6.1
qt6-gui-private-devel-6.2.2-150400.4.6.1
qt6-kmssupport-devel-static-6.2.2-150400.4.6.1
qt6-kmssupport-private-devel-6.2.2-150400.4.6.1
qt6-network-devel-6.2.2-150400.4.6.1
qt6-network-tls-6.2.2-150400.4.6.1
qt6-opengl-devel-6.2.2-150400.4.6.1
qt6-opengl-private-devel-6.2.2-150400.4.6.1
qt6-openglwidgets-devel-6.2.2-150400.4.6.1
qt6-platformsupport-devel-static-6.2.2-150400.4.6.1
qt6-printsupport-devel-6.2.2-150400.4.6.1
qt6-sql-devel-6.2.2-150400.4.6.1
qt6-sql-sqlite-6.2.2-150400.4.6.1
qt6-test-devel-6.2.2-150400.4.6.1
qt6-widgets-devel-6.2.2-150400.4.6.1
qt6-widgets-private-devel-6.2.2-150400.4.6.1
qt6-xml-devel-6.2.2-150400.4.6.1
openSUSE Leap 15.4
libQt6Concurrent6-6.2.2-150400.4.6.1
libQt6Core6-6.2.2-150400.4.6.1
libQt6DBus6-6.2.2-150400.4.6.1
libQt6Gui6-6.2.2-150400.4.6.1
libQt6Network6-6.2.2-150400.4.6.1
libQt6OpenGL6-6.2.2-150400.4.6.1
libQt6OpenGLWidgets6-6.2.2-150400.4.6.1
libQt6PrintSupport6-6.2.2-150400.4.6.1
libQt6Sql6-6.2.2-150400.4.6.1
libQt6Test6-6.2.2-150400.4.6.1
libQt6Widgets6-6.2.2-150400.4.6.1
libQt6Xml6-6.2.2-150400.4.6.1
qt6-base-common-devel-6.2.2-150400.4.6.1
qt6-base-devel-6.2.2-150400.4.6.1
qt6-base-docs-html-6.2.2-150400.4.6.1
qt6-base-docs-qch-6.2.2-150400.4.6.1
qt6-base-examples-6.2.2-150400.4.6.1
qt6-base-private-devel-6.2.2-150400.4.6.1
qt6-concurrent-devel-6.2.2-150400.4.6.1
qt6-core-devel-6.2.2-150400.4.6.1
qt6-core-private-devel-6.2.2-150400.4.6.1
qt6-dbus-devel-6.2.2-150400.4.6.1
qt6-dbus-private-devel-6.2.2-150400.4.6.1
qt6-docs-common-6.2.2-150400.4.6.1
qt6-gui-devel-6.2.2-150400.4.6.1
qt6-gui-private-devel-6.2.2-150400.4.6.1
qt6-kmssupport-devel-static-6.2.2-150400.4.6.1
qt6-kmssupport-private-devel-6.2.2-150400.4.6.1
qt6-network-devel-6.2.2-150400.4.6.1
qt6-network-private-devel-6.2.2-150400.4.6.1
qt6-network-tls-6.2.2-150400.4.6.1
qt6-networkinformation-nm-6.2.2-150400.4.6.1
qt6-opengl-devel-6.2.2-150400.4.6.1
qt6-opengl-private-devel-6.2.2-150400.4.6.1
qt6-openglwidgets-devel-6.2.2-150400.4.6.1
qt6-platformsupport-devel-static-6.2.2-150400.4.6.1
qt6-platformsupport-private-devel-6.2.2-150400.4.6.1
qt6-platformtheme-gtk3-6.2.2-150400.4.6.1
qt6-platformtheme-xdgdesktopportal-6.2.2-150400.4.6.1
qt6-printsupport-cups-6.2.2-150400.4.6.1
qt6-printsupport-devel-6.2.2-150400.4.6.1
qt6-printsupport-private-devel-6.2.2-150400.4.6.1
qt6-sql-devel-6.2.2-150400.4.6.1
qt6-sql-mysql-6.2.2-150400.4.6.1
qt6-sql-postgresql-6.2.2-150400.4.6.1
qt6-sql-private-devel-6.2.2-150400.4.6.1
qt6-sql-sqlite-6.2.2-150400.4.6.1
qt6-sql-unixODBC-6.2.2-150400.4.6.1
qt6-test-devel-6.2.2-150400.4.6.1
qt6-test-private-devel-6.2.2-150400.4.6.1
qt6-widgets-devel-6.2.2-150400.4.6.1
qt6-widgets-private-devel-6.2.2-150400.4.6.1
qt6-xml-devel-6.2.2-150400.4.6.1
qt6-xml-private-devel-6.2.2-150400.4.6.1

Описание

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Concurrent6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Core6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6DBus6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Gui6-6.2.2-150400.4.6.1

Ссылки

Описание

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Concurrent6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Core6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6DBus6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Gui6-6.2.2-150400.4.6.1

Ссылки

Описание

An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Concurrent6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Core6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6DBus6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Gui6-6.2.2-150400.4.6.1

Ссылки

Описание

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Concurrent6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Core6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6DBus6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Gui6-6.2.2-150400.4.6.1

Ссылки

Описание

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Concurrent6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Core6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6DBus6-6.2.2-150400.4.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP4:libQt6Gui6-6.2.2-150400.4.6.1

Ссылки
Уязвимость SUSE-SU-2023:3380-1