Описание
Security update for libqt4
This update for libqt4 fixes the following issue
- CVE-2025-14575: local user can load rogue CA certificates as trusted system authority via a crafted file placed in the application's working directory (bsc#1265896).
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libqt4-4.8.7-8.25.1
libqt4-32bit-4.8.7-8.25.1
libqt4-devel-4.8.7-8.25.1
libqt4-devel-doc-4.8.7-8.25.1
libqt4-devel-doc-data-4.8.7-8.25.1
libqt4-private-headers-devel-4.8.7-8.25.1
libqt4-qt3support-4.8.7-8.25.1
libqt4-qt3support-32bit-4.8.7-8.25.1
libqt4-sql-4.8.7-8.25.1
libqt4-sql-32bit-4.8.7-8.25.1
libqt4-sql-mysql-4.8.7-8.25.1
libqt4-sql-sqlite-4.8.7-8.25.1
libqt4-x11-4.8.7-8.25.1
libqt4-x11-32bit-4.8.7-8.25.1
qt4-x11-tools-4.8.7-8.25.1
Ссылки
- Link for SUSE-SU-2026:3116-1
- E-Mail link for SUSE-SU-2026:3116-1
- SUSE Security Ratings
- SUSE Bug 1265896
- SUSE CVE CVE-2025-14575 page
Описание
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.
Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libqt4-32bit-4.8.7-8.25.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libqt4-4.8.7-8.25.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libqt4-devel-4.8.7-8.25.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libqt4-devel-doc-4.8.7-8.25.1
Ссылки
- CVE-2025-14575
- SUSE Bug 1265894