Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2873-1

Опубликовано: 12 авг. 2024
Источник: suse-cvrf

Описание

Security update for qt6-base

This update for qt6-base fixes the following issues:

  • CVE-2024-33861: Fixed an invalid pointer being passed as a callback which coud lead to modification of the stack (bsc#1223917)
  • CVE-2024-39936: Fixed information leakage due to process HTTP2 communication before encrypted() can be responded to (bsc#1227426)
  • CVE-2023-45935: Fixed NULL pointer dereference in QXcbConnection::initializeAllAtoms() due to anomalous behavior from the X server (bsc#1222120)

Список пакетов

SUSE Linux Enterprise Module for Desktop Applications 15 SP5
libQt6Core6-6.4.2-150500.3.20.2
libQt6DBus6-6.4.2-150500.3.20.2
libQt6Gui6-6.4.2-150500.3.20.2
libQt6Network6-6.4.2-150500.3.20.2
libQt6OpenGL6-6.4.2-150500.3.20.2
libQt6Widgets6-6.4.2-150500.3.20.2
qt6-network-tls-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Package Hub 15 SP5
libQt6Concurrent6-6.4.2-150500.3.20.2
libQt6Core6-6.4.2-150500.3.20.2
libQt6DBus6-6.4.2-150500.3.20.2
libQt6Gui6-6.4.2-150500.3.20.2
libQt6Network6-6.4.2-150500.3.20.2
libQt6OpenGL6-6.4.2-150500.3.20.2
libQt6OpenGLWidgets6-6.4.2-150500.3.20.2
libQt6PrintSupport6-6.4.2-150500.3.20.2
libQt6Sql6-6.4.2-150500.3.20.2
libQt6Test6-6.4.2-150500.3.20.2
libQt6Widgets6-6.4.2-150500.3.20.2
libQt6Xml6-6.4.2-150500.3.20.2
qt6-base-common-devel-6.4.2-150500.3.20.2
qt6-base-devel-6.4.2-150500.3.20.2
qt6-concurrent-devel-6.4.2-150500.3.20.2
qt6-core-devel-6.4.2-150500.3.20.2
qt6-core-private-devel-6.4.2-150500.3.20.2
qt6-dbus-devel-6.4.2-150500.3.20.2
qt6-gui-devel-6.4.2-150500.3.20.2
qt6-gui-private-devel-6.4.2-150500.3.20.2
qt6-kmssupport-devel-static-6.4.2-150500.3.20.2
qt6-kmssupport-private-devel-6.4.2-150500.3.20.2
qt6-network-devel-6.4.2-150500.3.20.2
qt6-network-tls-6.4.2-150500.3.20.2
qt6-opengl-devel-6.4.2-150500.3.20.2
qt6-opengl-private-devel-6.4.2-150500.3.20.2
qt6-openglwidgets-devel-6.4.2-150500.3.20.2
qt6-platformsupport-devel-static-6.4.2-150500.3.20.2
qt6-printsupport-devel-6.4.2-150500.3.20.2
qt6-sql-devel-6.4.2-150500.3.20.2
qt6-sql-sqlite-6.4.2-150500.3.20.2
qt6-test-devel-6.4.2-150500.3.20.2
qt6-widgets-devel-6.4.2-150500.3.20.2
qt6-widgets-private-devel-6.4.2-150500.3.20.2
qt6-xml-devel-6.4.2-150500.3.20.2
openSUSE Leap 15.5
libQt6Concurrent6-6.4.2-150500.3.20.2
libQt6Core6-6.4.2-150500.3.20.2
libQt6DBus6-6.4.2-150500.3.20.2
libQt6Gui6-6.4.2-150500.3.20.2
libQt6Network6-6.4.2-150500.3.20.2
libQt6OpenGL6-6.4.2-150500.3.20.2
libQt6OpenGLWidgets6-6.4.2-150500.3.20.2
libQt6PrintSupport6-6.4.2-150500.3.20.2
libQt6Sql6-6.4.2-150500.3.20.2
libQt6Test6-6.4.2-150500.3.20.2
libQt6Widgets6-6.4.2-150500.3.20.2
libQt6Xml6-6.4.2-150500.3.20.2
qt6-base-common-devel-6.4.2-150500.3.20.2
qt6-base-devel-6.4.2-150500.3.20.2
qt6-base-docs-html-6.4.2-150500.3.20.1
qt6-base-docs-qch-6.4.2-150500.3.20.1
qt6-base-examples-6.4.2-150500.3.20.2
qt6-base-private-devel-6.4.2-150500.3.20.2
qt6-concurrent-devel-6.4.2-150500.3.20.2
qt6-core-devel-6.4.2-150500.3.20.2
qt6-core-private-devel-6.4.2-150500.3.20.2
qt6-dbus-devel-6.4.2-150500.3.20.2
qt6-dbus-private-devel-6.4.2-150500.3.20.2
qt6-docs-common-6.4.2-150500.3.20.2
qt6-gui-devel-6.4.2-150500.3.20.2
qt6-gui-private-devel-6.4.2-150500.3.20.2
qt6-kmssupport-devel-static-6.4.2-150500.3.20.2
qt6-kmssupport-private-devel-6.4.2-150500.3.20.2
qt6-network-devel-6.4.2-150500.3.20.2
qt6-network-private-devel-6.4.2-150500.3.20.2
qt6-network-tls-6.4.2-150500.3.20.2
qt6-networkinformation-glib-6.4.2-150500.3.20.2
qt6-networkinformation-nm-6.4.2-150500.3.20.2
qt6-opengl-devel-6.4.2-150500.3.20.2
qt6-opengl-private-devel-6.4.2-150500.3.20.2
qt6-openglwidgets-devel-6.4.2-150500.3.20.2
qt6-platformsupport-devel-static-6.4.2-150500.3.20.2
qt6-platformsupport-private-devel-6.4.2-150500.3.20.2
qt6-platformtheme-gtk3-6.4.2-150500.3.20.2
qt6-platformtheme-xdgdesktopportal-6.4.2-150500.3.20.2
qt6-printsupport-cups-6.4.2-150500.3.20.2
qt6-printsupport-devel-6.4.2-150500.3.20.2
qt6-printsupport-private-devel-6.4.2-150500.3.20.2
qt6-sql-devel-6.4.2-150500.3.20.2
qt6-sql-mysql-6.4.2-150500.3.20.2
qt6-sql-postgresql-6.4.2-150500.3.20.2
qt6-sql-private-devel-6.4.2-150500.3.20.2
qt6-sql-sqlite-6.4.2-150500.3.20.2
qt6-sql-unixODBC-6.4.2-150500.3.20.2
qt6-test-devel-6.4.2-150500.3.20.2
qt6-test-private-devel-6.4.2-150500.3.20.2
qt6-widgets-devel-6.4.2-150500.3.20.2
qt6-widgets-private-devel-6.4.2-150500.3.20.2
qt6-xml-devel-6.4.2-150500.3.20.2
qt6-xml-private-devel-6.4.2-150500.3.20.2

Описание

** DISPUTED ** Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Core6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6DBus6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Gui6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Network6-6.4.2-150500.3.20.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Core6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6DBus6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Gui6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Network6-6.4.2-150500.3.20.2

Ссылки

Описание

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..


Затронутые продукты
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Core6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6DBus6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Gui6-6.4.2-150500.3.20.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5:libQt6Network6-6.4.2-150500.3.20.2

Ссылки
Уязвимость SUSE-SU-2024:2873-1