Описание
Security update for libqt5-qtbase
This update for libqt5-qtbase fixes the following issues:
- CVE-2023-37369: Fixed a buffer overflow in QXmlStreamReader (QTBUG-91889, bsc#1214327).
- CVE-2023-45935: Fixed NULL pointer dereference in QXcbConnection::initializeAllAtoms() due to anomalous behavior from the X server (bsc#1222120)
- CVE-2024-39936: Fixed information leakage due to process HTTP2 communication before encrypted() can be responded to (bsc#1227426)
- CVE-2023-51714: Fixed an incorrect integer overflow check (bsc#1218413).
Other fixes:
- Add patch from upstream to fix a regression in the ODBC driver (bsc#1227513, QTBUG-112375)
- Add upstream patch to fix a potential overflow in assemble_hpack_block()
- Use pkgconfig(icu-18n) to select current icu
Список пакетов
Image SLES15-SP3-SAP-BYOS-Azure
Image SLES15-SP3-SAP-BYOS-EC2-HVM
Image SLES15-SP3-SAP-BYOS-GCE
SUSE Enterprise Storage 7.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
SUSE Linux Enterprise Server 15 SP2-LTSS
SUSE Linux Enterprise Server 15 SP3-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
Ссылки
- Link for SUSE-SU-2024:2946-1
- E-Mail link for SUSE-SU-2024:2946-1
- SUSE Security Ratings
- SUSE Bug 1214327
- SUSE Bug 1218413
- SUSE Bug 1222120
- SUSE Bug 1227426
- SUSE Bug 1227513
- SUSE CVE CVE-2023-37369 page
- SUSE CVE CVE-2023-45935 page
- SUSE CVE CVE-2023-51714 page
- SUSE CVE CVE-2024-39936 page
Описание
In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.
Затронутые продукты
Ссылки
- CVE-2023-37369
- SUSE Bug 1214327
Описание
** DISPUTED ** Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.
Затронутые продукты
Ссылки
- CVE-2023-45935
- SUSE Bug 1222120
Описание
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
Затронутые продукты
Ссылки
- CVE-2023-51714
- SUSE Bug 1218413
Описание
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..
Затронутые продукты
Ссылки
- CVE-2024-39936
- SUSE Bug 1227426