ELSA-2023-6967

ELSA-2023-6967 - qt5-qtbase security update

Type:SECURITY
Severity:MODERATE
Release Date:2023-11-17

Description


[5.15.3-5]
- Fix infinite loops in QXmlStreamReader (CVE-2023-38197)
Resolves: bz#2222770

[5.15.3-4]
- Don't allow remote attacker to bypass security restrictions caused by
flaw in certificate validation (CVE-2023-34410) (version #2)
Resolves: bz#2212753

[5.15.3-3]
- Don't allow remote attacker to bypass security restrictions caused by
flaw in certificate validation (CVE-2023-34410)
Resolves: bz#2212753

[5.15.3-2]
- Fix specific overflow in qtextlayout
- Fix incorrect parsing of the strict-transport-security (HSTS) header
- Fix buffer over-read via a crafted reply from a DNS server
Resolves: bz#2209491


Related CVEs


CVE-2023-34410
CVE-2023-33285
CVE-2023-37369
CVE-2023-38197

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) qt5-qtbase-5.15.3-5.el8.src.rpm6413286e893fcd8851ce0f725c67d0e2-ol8_aarch64_appstream
qt5-qtbase-5.15.3-5.el8.src.rpm6413286e893fcd8851ce0f725c67d0e2-ol8_aarch64_codeready_builder
qt5-qtbase-5.15.3-5.el8.aarch64.rpmc6a27c117319e0a87fab99b8d8ca2ec7-ol8_aarch64_appstream
qt5-qtbase-common-5.15.3-5.el8.noarch.rpm9596ef536d63a0e0de17aaad56180415-ol8_aarch64_appstream
qt5-qtbase-devel-5.15.3-5.el8.aarch64.rpmf48af2bb21512d6bea4042215cfff9f9-ol8_aarch64_appstream
qt5-qtbase-examples-5.15.3-5.el8.aarch64.rpm02195b337adf9cca4de9f5c0b40e8019-ol8_aarch64_appstream
qt5-qtbase-gui-5.15.3-5.el8.aarch64.rpm35c9c443b83c7299303f0c0dd6c5a8e9-ol8_aarch64_appstream
qt5-qtbase-mysql-5.15.3-5.el8.aarch64.rpm41c486fc6c46503cb811afaf68cb2ff9-ol8_aarch64_appstream
qt5-qtbase-odbc-5.15.3-5.el8.aarch64.rpm13986f535f10576ba84dc3f144cd2cc7-ol8_aarch64_appstream
qt5-qtbase-postgresql-5.15.3-5.el8.aarch64.rpm70047f11a737e3e59475c81edcc69079-ol8_aarch64_appstream
qt5-qtbase-private-devel-5.15.3-5.el8.aarch64.rpm85e68dd9d9de78cdc0b56aea7e7a209f-ol8_aarch64_appstream
qt5-qtbase-static-5.15.3-5.el8.aarch64.rpm2fb51c2eae2d61d6968e9cfd022dac9b-ol8_aarch64_codeready_builder
Oracle Linux 8 (x86_64) qt5-qtbase-5.15.3-5.el8.src.rpm6413286e893fcd8851ce0f725c67d0e2-ol8_x86_64_appstream
qt5-qtbase-5.15.3-5.el8.src.rpm6413286e893fcd8851ce0f725c67d0e2-ol8_x86_64_codeready_builder
qt5-qtbase-5.15.3-5.el8.i686.rpm69b08a9635bcd9bcf1345f5582f55f00-ol8_x86_64_appstream
qt5-qtbase-5.15.3-5.el8.x86_64.rpm65940fe3ef150e887ea8797748f07b65-ol8_x86_64_appstream
qt5-qtbase-common-5.15.3-5.el8.noarch.rpm9596ef536d63a0e0de17aaad56180415-ol8_x86_64_appstream
qt5-qtbase-devel-5.15.3-5.el8.i686.rpm160c9895b8c87a853116b50ceef748cb-ol8_x86_64_appstream
qt5-qtbase-devel-5.15.3-5.el8.x86_64.rpmdae3f6c535c5005cfa7e672839443f68-ol8_x86_64_appstream
qt5-qtbase-examples-5.15.3-5.el8.i686.rpm42157f8af96936e1b3251febf8e41c73-ol8_x86_64_appstream
qt5-qtbase-examples-5.15.3-5.el8.x86_64.rpm37e3db45105bb6f43c084a37c7f74fe2-ol8_x86_64_appstream
qt5-qtbase-gui-5.15.3-5.el8.i686.rpm5e2ab3110ce2f3b9a8376e4c6261fd7b-ol8_x86_64_appstream
qt5-qtbase-gui-5.15.3-5.el8.x86_64.rpm4b3835d57a6fb5f6dc2e9f047c7727a6-ol8_x86_64_appstream
qt5-qtbase-mysql-5.15.3-5.el8.i686.rpm7ffc9d531cd06e9147fb3306cf209bf3-ol8_x86_64_appstream
qt5-qtbase-mysql-5.15.3-5.el8.x86_64.rpm334498dc1b731c91237c96d795234e12-ol8_x86_64_appstream
qt5-qtbase-odbc-5.15.3-5.el8.i686.rpma52cf0997670994071d784ee4f2e2759-ol8_x86_64_appstream
qt5-qtbase-odbc-5.15.3-5.el8.x86_64.rpm023293a09da911323df52db66d990d6b-ol8_x86_64_appstream
qt5-qtbase-postgresql-5.15.3-5.el8.i686.rpma0f22f3ece5c17bd9b12c663da6467ca-ol8_x86_64_appstream
qt5-qtbase-postgresql-5.15.3-5.el8.x86_64.rpm3128e53726fc1cf6038749dc8097de32-ol8_x86_64_appstream
qt5-qtbase-private-devel-5.15.3-5.el8.i686.rpmd1101b103294f16b13ca72f947bfc58d-ol8_x86_64_appstream
qt5-qtbase-private-devel-5.15.3-5.el8.x86_64.rpm2deda8d46f9a92334f2135e038f73403-ol8_x86_64_appstream
qt5-qtbase-static-5.15.3-5.el8.i686.rpmdf578f3d05bd9e3f93eed311414a96c5-ol8_x86_64_codeready_builder
qt5-qtbase-static-5.15.3-5.el8.x86_64.rpm79c3c7ed8549e17019cb281353e822d4-ol8_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete