SUSE-SU-2023:4622-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4622-1
SUSE-SU-2023:4622-1
Summary: Security update for libqt4
Details: This update for libqt4 fixes the following issues: - CVE-2021-45930: Fix out of-bounds write when parsing path nodes (bsc#1196654). - CVE-2023-32573: Fix missing initialization of QSvgFont unitsPerEm (bsc#1211298). - CVE-2023-32763: Fix potential buffer when rendering a SVG file with an image inside (bsc#1211798). - CVE-2023-34410: Fix missing sync of disablement of loading root certificates in qsslsocketprivate (bsc#1211994). - CVE-2023-37369: Fix buffer overflow in QXmlStreamReader (bsc#1214327). - CVE-2023-38197: Fix infinite loops in QXmlStreamReader (bsc#1213326).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234622-1/, https://bugzilla.suse.com/1196654, https://bugzilla.suse.com/1211298, https://bugzilla.suse.com/1211798, https://bugzilla.suse.com/1211994, https://bugzilla.suse.com/1213326, https://bugzilla.suse.com/1214327, https://www.suse.com/security/cve/CVE-2021-45930, https://www.suse.com/security/cve/CVE-2023-32573, https://www.suse.com/security/cve/CVE-2023-32763, https://www.suse.com/security/cve/CVE-2023-34410, https://www.suse.com/security/cve/CVE-2023-37369, https://www.suse.com/security/cve/CVE-2023-38197
Affected packages
Package
Name: libqt4
Purl: pkg:rpm/suse/libqt4&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
