Описание
Security update for qt6-base
This update for qt6-base fixes the following issues:
- CVE-2024-33861: Fixed an invalid pointer being passed as a callback which coud lead to modification of the stack (bsc#1223917)
- CVE-2024-39936: Fixed information leakage due to process HTTP2 communication before encrypted() can be responded to (bsc#1227426)
- CVE-2023-45935: Fixed NULL pointer dereference in QXcbConnection::initializeAllAtoms() due to anomalous behavior from the X server (bsc#1222120)
Список пакетов
SUSE Linux Enterprise Module for Desktop Applications 15 SP5
SUSE Linux Enterprise Module for Package Hub 15 SP5
openSUSE Leap 15.5
Ссылки
- Link for SUSE-SU-2024:2873-1
- E-Mail link for SUSE-SU-2024:2873-1
- SUSE Security Ratings
- SUSE Bug 1222120
- SUSE Bug 1223917
- SUSE Bug 1227426
- SUSE CVE CVE-2023-45935 page
- SUSE CVE CVE-2024-33861 page
- SUSE CVE CVE-2024-39936 page
Описание
** DISPUTED ** Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.
Затронутые продукты
Ссылки
- CVE-2023-45935
- SUSE Bug 1222120
Описание
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Затронутые продукты
Ссылки
- CVE-2024-33861
- SUSE Bug 1223917
Описание
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..
Затронутые продукты
Ссылки
- CVE-2024-39936
- SUSE Bug 1227426