SUSE-SU-2023:2982-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2982-1
SUSE-SU-2023:2982-1
Summary: Security update for libqt5-qtbase
Details: This update for libqt5-qtbase fixes the following issues: - CVE-2023-24607: Fixed Qt SQL ODBC driver plugin DOS (bsc#1209616). - CVE-2023-32762: Fixed Qt Network incorrectly parses the strict-transport-security (HSTS) header (bsc#1211797). - CVE-2023-32763: Fixed buffer overflow when rendering an SVG file with an image inside it (bsc#1211798). - CVE-2023-33285: Fixed buffer overflow in QDnsLookup (bsc#1211642). - CVE-2023-34410: Fixed certificate validation does not always consider whether the root of a chain is a configured CA certificate (bsc#1211994). - CVE-2023-38197: Fixed infinite loops in QXmlStreamReader(bsc#1213326).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232982-1/, https://bugzilla.suse.com/1209616, https://bugzilla.suse.com/1211024, https://bugzilla.suse.com/1211642, https://bugzilla.suse.com/1211797, https://bugzilla.suse.com/1211798, https://bugzilla.suse.com/1211994, https://bugzilla.suse.com/1213326, https://www.suse.com/security/cve/CVE-2023-24607, https://www.suse.com/security/cve/CVE-2023-32762, https://www.suse.com/security/cve/CVE-2023-32763, https://www.suse.com/security/cve/CVE-2023-33285, https://www.suse.com/security/cve/CVE-2023-34410, https://www.suse.com/security/cve/CVE-2023-38197
Affected packages
Package
Name: libqt5-qtbase
Purl: pkg:rpm/suse/libqt5-qtbase&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
