CVE-2023-37369
Summary
| CVE | CVE-2023-37369 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-20 07:15:00 UTC |
| Updated | 2023-11-07 04:16:00 UTC |
| Description | In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Application | Qt | Qt | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 38 Update: mingw-qt5-qtbase-5.15.10-4.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] [DLA 3539-1] qt4-x11 security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 38 Update: mingw-qt5-qtbase-5.15.10-4.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Loading... | MISC | bugreports.qt.io | |
| [SECURITY] Fedora 37 Update: mingw-qt5-qtbase-5.15.10-4.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| codereview.qt-project.org/c/qt/qtbase/+/455027 | MISC | codereview.qt-project.org | |
| [SECURITY] Fedora 37 Update: mingw-qt5-qtbase-5.15.10-4.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161064 Oracle Enterprise Linux Security Update for qt5 (ELSA-2023-6369)
- 161142 Oracle Enterprise Linux Security Update for qt5-qtbase (ELSA-2023-6967)
- 242300 Red Hat Update for qt5 (RHSA-2023:6369)
- 242424 Red Hat Update for qt5-qtbase (RHSA-2023:6967)
- 284418 Fedora Security Update for qt5 (FEDORA-2023-04d519d0b3)
- 296105 Oracle Solaris 11.4 Support Repository Update (SRU) 63.157.1 Missing (CPUOCT2023)
- 6000048 Debian Security Update for qt4-x11 (DLA 3539-1)
- 673688 EulerOS Security Update for qt5-qtbase (EulerOS-SA-2023-3155)
- 755524 SUSE Enterprise Linux Security Update for libqt5-qtbase (SUSE-SU-2023:4951-1)
- 755526 SUSE Enterprise Linux Security Update for libqt5-qtbase (SUSE-SU-2023:4950-1)
- 907222 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (27920-1)
- 941352 AlmaLinux Security Update for qt5 (ALSA-2023:6369)
- 941424 AlmaLinux Security Update for qt5-qtbase (ALSA-2023:6967)