rpm package
opensuse/qt6-base-docs&distro=openSUSE Leap 15.4
pkg:rpm/opensuse/qt6-base-docs&distro=openSUSE%20Leap%2015.4
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-38197 | — | < 6.2.2-150400.4.6.1 | 6.2.2-150400.4.6.1 | Jul 13, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion. | ||
| CVE-2023-34410 | — | < 6.2.2-150400.4.6.1 | 6.2.2-150400.4.6.1 | Jun 5, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. | ||
| CVE-2023-32763 | — | < 6.2.2-150400.4.6.1 | 6.2.2-150400.4.6.1 | May 28, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered. | ||
| CVE-2023-32762 | — | < 6.2.2-150400.4.6.1 | 6.2.2-150400.4.6.1 | May 28, 2023 | An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This | ||
| CVE-2023-33285 | — | < 6.2.2-150400.4.6.1 | 6.2.2-150400.4.6.1 | May 22, 2023 | An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server. | ||
| CVE-2023-24607 | — | < 6.2.2-150400.4.3.1 | 6.2.2-150400.4.3.1 | Apr 15, 2023 | Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3. |
- CVE-2023-38197Jul 13, 2023affected < 6.2.2-150400.4.6.1fixed 6.2.2-150400.4.6.1
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
- CVE-2023-34410Jun 5, 2023affected < 6.2.2-150400.4.6.1fixed 6.2.2-150400.4.6.1
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
- CVE-2023-32763May 28, 2023affected < 6.2.2-150400.4.6.1fixed 6.2.2-150400.4.6.1
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
- CVE-2023-32762May 28, 2023affected < 6.2.2-150400.4.6.1fixed 6.2.2-150400.4.6.1
An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This
- CVE-2023-33285May 22, 2023affected < 6.2.2-150400.4.6.1fixed 6.2.2-150400.4.6.1
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
- CVE-2023-24607Apr 15, 2023affected < 6.2.2-150400.4.3.1fixed 6.2.2-150400.4.3.1
Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.