Vulnerability CVE-2023-37369: Information

Description

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 20, 2023
Modified: May 1, 2024

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
qt5-webenginesisyphus5.15.15-alt15.15.16-alt5ALT-PU-2023-5566-1329396Fixed
qt5-webenginep105.15.15-alt15.15.16-alt4ALT-PU-2023-5570-2329398Fixed
qt5-webenginep115.15.15-alt15.15.16-alt5ALT-PU-2023-5566-1329396Fixed
qt6-3dsisyphus6.6.0-alt16.6.2-alt1.1ALT-PU-2023-7237-1334016Fixed
qt6-3dsisyphus_e2k6.6.1-alt1.16.6.2-alt1.1ALT-PU-2024-2658-1-Fixed
qt6-3dsisyphus_riscv646.6.0-alt16.6.2-alt1.1ALT-PU-2023-7352-1-Fixed
qt6-3dp116.6.0-alt16.6.2-alt1.1ALT-PU-2023-7237-1334016Fixed
qt6-5compatsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7228-1334016Fixed
qt6-5compatsisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2636-1-Fixed
qt6-5compatsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7349-1-Fixed
qt6-5compatp116.6.0-alt16.6.2-alt1ALT-PU-2023-7228-1334016Fixed
qt6-basesisyphus6.6.0-alt16.6.2-alt3ALT-PU-2023-7225-1334016Fixed
qt6-basesisyphus_e2k6.6.1-alt1.E2K.16.6.2-alt3.E2K.2ALT-PU-2024-2656-1-Fixed
qt6-basesisyphus_riscv646.6.0-alt16.6.2-alt3ALT-PU-2023-7350-1-Fixed
qt6-basep106.4.2-alt56.4.2-alt5ALT-PU-2024-3485-2342087Fixed
qt6-basep10_e2k6.4.2-alt5.E2K.16.4.2-alt5.E2K.1ALT-PU-2024-4219-1-Fixed
qt6-basep116.6.0-alt16.6.2-alt3ALT-PU-2023-7225-1334016Fixed
qt6-chartssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7235-1334016Fixed
qt6-chartssisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2645-1-Fixed
qt6-chartssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7353-1-Fixed
qt6-chartsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7235-1334016Fixed
qt6-connectivitysisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7231-1334016Fixed
qt6-connectivitysisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2642-1-Fixed
qt6-connectivitysisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7342-1-Fixed
qt6-connectivityp116.6.0-alt16.6.2-alt1ALT-PU-2023-7231-1334016Fixed
qt6-datavis3dsisyphus6.6.1-alt16.6.2-alt1ALT-PU-2024-1120-1338043Fixed
qt6-datavis3dsisyphus_riscv646.6.1-alt16.6.2-alt1ALT-PU-2024-1133-1-Fixed
qt6-datavis3dsisyphus_loongarch646.6.1-alt16.6.2-alt1ALT-PU-2024-1141-1-Fixed
qt6-datavis3dp116.6.1-alt16.6.2-alt1ALT-PU-2024-1120-1338043Fixed
qt6-declarativesisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7215-1334016Fixed
qt6-declarativesisyphus_e2k6.6.1-alt26.6.2-alt1ALT-PU-2024-2651-1-Fixed
qt6-declarativesisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7334-1-Fixed
qt6-declarativep116.6.0-alt16.6.2-alt1ALT-PU-2023-7215-1334016Fixed
qt6-imageformatssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7220-1334016Fixed
qt6-imageformatssisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2641-1-Fixed
qt6-imageformatssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7341-1-Fixed
qt6-imageformatsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7220-1334016Fixed
qt6-multimediasisyphus6.6.0-alt16.6.2-alt1.1ALT-PU-2023-7217-1334016Fixed
qt6-multimediasisyphus_e2k6.6.1-alt1.16.6.2-alt1.1ALT-PU-2024-2657-1-Fixed
qt6-multimediasisyphus_riscv646.6.0-alt16.6.2-alt1.1ALT-PU-2023-7337-1-Fixed
qt6-multimediap116.6.0-alt16.6.2-alt1.1ALT-PU-2023-7217-1334016Fixed
qt6-networkauthsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7236-1334016Fixed
qt6-networkauthsisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2647-1-Fixed
qt6-networkauthsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7347-1-Fixed
qt6-networkauthp116.6.0-alt16.6.2-alt1ALT-PU-2023-7236-1334016Fixed
qt6-positioningsisyphus6.6.0-alt16.6.2-alt1.1ALT-PU-2023-7222-1334016Fixed
qt6-positioningsisyphus_riscv646.6.0-alt16.6.2-alt1.1ALT-PU-2023-7344-1-Fixed
qt6-positioningp116.6.0-alt16.6.2-alt1.1ALT-PU-2023-7222-1334016Fixed
qt6-quicktimelinesisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7224-1334016Fixed
qt6-quicktimelinesisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2644-1-Fixed
qt6-quicktimelinesisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7348-1-Fixed
qt6-quicktimelinep116.6.0-alt16.6.2-alt1ALT-PU-2023-7224-1334016Fixed
qt6-remoteobjectssisyphus6.6.2-alt16.6.2-alt1ALT-PU-2024-2801-1341139Fixed
qt6-remoteobjectssisyphus_e2k6.6.2-alt16.6.2-alt1ALT-PU-2024-2982-1-Fixed
qt6-remoteobjectssisyphus_riscv646.6.2-alt16.6.2-alt1ALT-PU-2024-3743-1-Fixed
qt6-remoteobjectssisyphus_loongarch646.6.2-alt16.6.2-alt1ALT-PU-2024-2916-1-Fixed
qt6-remoteobjectsp116.6.2-alt16.6.2-alt1ALT-PU-2024-2801-1341139Fixed
qt6-scxmlsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7234-1334016Fixed
qt6-scxmlsisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2643-1-Fixed
qt6-scxmlsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7345-1-Fixed
qt6-scxmlp116.6.0-alt16.6.2-alt1ALT-PU-2023-7234-1334016Fixed
qt6-sensorssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7221-1334016Fixed
qt6-sensorssisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2640-1-Fixed
qt6-sensorssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7343-1-Fixed
qt6-sensorsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7221-1334016Fixed
qt6-serialportsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7230-1334016Fixed
qt6-serialportsisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2639-1-Fixed
qt6-serialportsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7340-1-Fixed
qt6-serialportp116.6.0-alt16.6.2-alt1ALT-PU-2023-7230-1334016Fixed
qt6-shadertoolssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7226-1334016Fixed
qt6-shadertoolssisyphus_e2k6.6.1-alt26.6.2-alt1ALT-PU-2024-2652-1-Fixed
qt6-shadertoolssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7333-1-Fixed
qt6-shadertoolsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7226-1334016Fixed
qt6-svgsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7227-1334016Fixed
qt6-svgsisyphus_e2k6.6.1-alt36.6.2-alt1ALT-PU-2024-2649-1-Fixed
qt6-svgsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7336-1-Fixed
qt6-svgp116.6.0-alt16.6.2-alt1ALT-PU-2023-7227-1334016Fixed
qt6-toolssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7216-1334016Fixed
qt6-toolssisyphus_e2k6.6.1-alt26.6.2-alt1ALT-PU-2024-2650-1-Fixed
qt6-toolssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7351-1-Fixed
qt6-toolsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7216-1334016Fixed
qt6-translationssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7223-1334016Fixed
qt6-translationssisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2634-1-Fixed
qt6-translationssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7335-1-Fixed
qt6-translationsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7223-1334016Fixed
qt6-virtualkeyboardsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7233-1334016Fixed
qt6-virtualkeyboardsisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2646-1-Fixed
qt6-virtualkeyboardsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7346-1-Fixed
qt6-virtualkeyboardp116.6.0-alt16.6.2-alt1ALT-PU-2023-7233-1334016Fixed
qt6-waylandsisyphus6.6.0-alt16.6.2-alt2ALT-PU-2023-7219-1334016Fixed
qt6-waylandsisyphus_e2k6.6.1-alt16.6.2-alt2ALT-PU-2024-2648-1-Fixed
qt6-waylandsisyphus_riscv646.6.0-alt16.6.2-alt2ALT-PU-2023-7339-1-Fixed
qt6-waylandp116.6.0-alt16.6.2-alt2ALT-PU-2023-7219-1334016Fixed
qt6-webchannelsisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7218-1334016Fixed
qt6-webchannelsisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2638-1-Fixed
qt6-webchannelsisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7354-1-Fixed
qt6-webchannelp116.6.0-alt16.6.2-alt1ALT-PU-2023-7218-1334016Fixed
qt6-webenginesisyphus6.6.0-alt16.6.2-alt3ALT-PU-2023-7232-1334016Fixed
qt6-webenginep116.6.0-alt16.6.2-alt3ALT-PU-2023-7232-1334016Fixed
qt6-websocketssisyphus6.6.0-alt16.6.2-alt1ALT-PU-2023-7229-1334016Fixed
qt6-websocketssisyphus_e2k6.6.1-alt16.6.2-alt1ALT-PU-2024-2637-1-Fixed
qt6-websocketssisyphus_riscv646.6.0-alt16.6.2-alt1ALT-PU-2023-7338-1-Fixed
qt6-websocketsp116.6.0-alt16.6.2-alt1ALT-PU-2023-7229-1334016Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
      Start including
      6.0.0
      End excliding
      6.2.9

      cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
      End excliding
      5.15.15

      cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
      Start including
      6.3.0
      End excliding
      6.5.2

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*