SUSE-SU-2023:3225-1
Dashboard / Vulnerabilities / SUSE-SU-2023:3225-1
SUSE-SU-2023:3225-1
Summary: Security update for qt6-base
Details: This update for qt6-base fixes the following issues: - CVE-2023-34410: Fixed certificate validation does not always consider whether the root of a chain is a configured CA certificate (bsc#1211994). - CVE-2023-33285: Fixed buffer overflow in QDnsLookup (bsc#1211642). - CVE-2023-32762: Fixed Qt Network incorrectly parses the strict-transport-security (HSTS) header (bsc#1211797). - CVE-2023-38197: Fixed infinite loops in QXmlStreamReader(bsc#1213326). - CVE-2023-24607: Fixed Qt SQL ODBC driver plugin DOS (bsc#1209616).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20233225-1/, https://bugzilla.suse.com/1209616, https://bugzilla.suse.com/1211642, https://bugzilla.suse.com/1211797, https://bugzilla.suse.com/1211994, https://bugzilla.suse.com/1213326, https://www.suse.com/security/cve/CVE-2023-24607, https://www.suse.com/security/cve/CVE-2023-32762, https://www.suse.com/security/cve/CVE-2023-33285, https://www.suse.com/security/cve/CVE-2023-34410, https://www.suse.com/security/cve/CVE-2023-38197
Affected packages
Package
Name: qt6-base
Purl: pkg:rpm/suse/qt6-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
