SUSE-SU-2023:3207-1
Dashboard / Vulnerabilities / SUSE-SU-2023:3207-1
SUSE-SU-2023:3207-1
Summary: Security update for libqt5-qtbase
Details: This update for libqt5-qtbase fixes the following issues: - CVE-2023-34410: Fixed certificate validation does not always consider whether the root of a chain is a configured CA certificate (bsc#1211994). - CVE-2023-33285: Fixed buffer overflow in QDnsLookup (bsc#1211642). - CVE-2023-32762: Fixed Qt Network incorrectly parses the strict-transport-security (HSTS) header (bsc#1211797). - CVE-2023-38197: Fixed infinite loops in QXmlStreamReader(bsc#1213326). - CVE-2023-24607: Fixed Qt SQL ODBC driver plugin DOS (bsc#1209616).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20233207-1/, https://bugzilla.suse.com/1209616, https://bugzilla.suse.com/1211642, https://bugzilla.suse.com/1211797, https://bugzilla.suse.com/1211994, https://bugzilla.suse.com/1213326, https://www.suse.com/security/cve/CVE-2023-24607, https://www.suse.com/security/cve/CVE-2023-32762, https://www.suse.com/security/cve/CVE-2023-33285, https://www.suse.com/security/cve/CVE-2023-34410, https://www.suse.com/security/cve/CVE-2023-38197
Affected packages
Package
Name: libqt5-qtbase
Purl: pkg:rpm/suse/libqt5-qtbase&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSS
Affected ranges
Type: ECOSYSTEM
Events:
