319 lines
15 KiB
JSON
319 lines
15 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20241221",
|
||
"Version": "oval:org.altlinux.errata:def:20241221",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2024-1221: package `qt6-base` update to version 6.4.2-alt4",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c10f2"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2024-1221",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-1221",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-02373",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-02373",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03689",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03689",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03802",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03802",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03803",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03803",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03876",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03876",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-24607",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-24607",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-32762",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-32762",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-32763",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-32763",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-33285",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-33285",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-34410",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-34410",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades qt6-base to version 6.4.2-alt4. \nSecurity Fix(es):\n\n * BDU:2023-02373: Уязвимость плагина SQL ODBC кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2023-03689: Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти существующие ограничения безопасности\n\n * BDU:2023-03802: Уязвимость компонента QTextLayout кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2023-03803: Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с передачей защищаемой информации в незашифрованном виде, позволяющая нарушителю оказать воздействие на целостность данных\n\n * BDU:2023-03876: Уязвимость компонента QDnsLookup кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2023-24607: Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.\n\n * CVE-2023-32762: An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.\n\n * CVE-2023-32763: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.\n\n * CVE-2023-33285: An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.\n\n * CVE-2023-34410: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.\n\n * #46477: qt6-base: ошибка сборки на архитектуре LoongArch",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "High",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2024-01-22"
|
||
},
|
||
"Updated": {
|
||
"Date": "2024-01-22"
|
||
},
|
||
"bdu": [
|
||
{
|
||
"Cvss": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
|
||
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"Cwe": "CWE-20, CWE-404",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-02373",
|
||
"Impact": "High",
|
||
"Public": "20230415",
|
||
"CveID": "BDU:2023-02373"
|
||
},
|
||
{
|
||
"Cvss": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
|
||
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
||
"Cwe": "CWE-295",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03689",
|
||
"Impact": "Low",
|
||
"Public": "20230604",
|
||
"CveID": "BDU:2023-03689"
|
||
},
|
||
{
|
||
"Cvss": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
|
||
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"Cwe": "CWE-120",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03802",
|
||
"Impact": "High",
|
||
"Public": "20230522",
|
||
"CveID": "BDU:2023-03802"
|
||
},
|
||
{
|
||
"Cvss": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
|
||
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
||
"Cwe": "CWE-319",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03803",
|
||
"Impact": "Low",
|
||
"Public": "20230508",
|
||
"CveID": "BDU:2023-03803"
|
||
},
|
||
{
|
||
"Cvss": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
||
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
|
||
"Cwe": "CWE-125",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03876",
|
||
"Impact": "Low",
|
||
"Public": "20230512",
|
||
"CveID": "BDU:2023-03876"
|
||
}
|
||
],
|
||
"Cves": [
|
||
{
|
||
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"Cwe": "NVD-CWE-noinfo",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-24607",
|
||
"Impact": "High",
|
||
"Public": "20230415",
|
||
"CveID": "CVE-2023-24607"
|
||
},
|
||
{
|
||
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
||
"Cwe": "NVD-CWE-noinfo",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-32762",
|
||
"Impact": "Low",
|
||
"Public": "20230528",
|
||
"CveID": "CVE-2023-32762"
|
||
},
|
||
{
|
||
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"Cwe": "CWE-120",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-32763",
|
||
"Impact": "High",
|
||
"Public": "20230528",
|
||
"CveID": "CVE-2023-32763"
|
||
},
|
||
{
|
||
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
|
||
"Cwe": "CWE-125",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-33285",
|
||
"Impact": "Low",
|
||
"Public": "20230522",
|
||
"CveID": "CVE-2023-33285"
|
||
},
|
||
{
|
||
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
||
"Cwe": "CWE-295",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-34410",
|
||
"Impact": "Low",
|
||
"Public": "20230605",
|
||
"CveID": "CVE-2023-34410"
|
||
}
|
||
],
|
||
"Bugzilla": [
|
||
{
|
||
"Id": "46477",
|
||
"Href": "https://bugzilla.altlinux.org/46477",
|
||
"Data": "qt6-base: ошибка сборки на архитектуре LoongArch"
|
||
}
|
||
],
|
||
"AffectedCpeList": {
|
||
"Cpe": [
|
||
"cpe:/o:alt:spworkstation:10",
|
||
"cpe:/o:alt:spserver:10"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:5001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221001",
|
||
"Comment": "libqt6-concurrent is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221002",
|
||
"Comment": "libqt6-core is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221003",
|
||
"Comment": "libqt6-dbus is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221004",
|
||
"Comment": "libqt6-eglfsdeviceintegration is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221005",
|
||
"Comment": "libqt6-eglfskmsgbmsupport is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221006",
|
||
"Comment": "libqt6-eglfskmssupport is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221007",
|
||
"Comment": "libqt6-gui is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221008",
|
||
"Comment": "libqt6-network is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221009",
|
||
"Comment": "libqt6-opengl is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221010",
|
||
"Comment": "libqt6-openglwidgets is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221011",
|
||
"Comment": "libqt6-printsupport is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221012",
|
||
"Comment": "libqt6-sql is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221013",
|
||
"Comment": "libqt6-test is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221014",
|
||
"Comment": "libqt6-widgets is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221015",
|
||
"Comment": "libqt6-xcbqpa is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221016",
|
||
"Comment": "libqt6-xml is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221017",
|
||
"Comment": "qt6-base-common is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221018",
|
||
"Comment": "qt6-base-devel is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221019",
|
||
"Comment": "qt6-base-devel-static is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221020",
|
||
"Comment": "qt6-base-doc is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221021",
|
||
"Comment": "qt6-qtbase is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221022",
|
||
"Comment": "qt6-qtbase-gui is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221023",
|
||
"Comment": "qt6-sql is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221024",
|
||
"Comment": "qt6-sql-interbase is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221025",
|
||
"Comment": "qt6-sql-mysql is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221026",
|
||
"Comment": "qt6-sql-odbc is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221027",
|
||
"Comment": "qt6-sql-postgresql is earlier than 0:6.4.2-alt4"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20241221028",
|
||
"Comment": "rpm-macros-qt6 is earlier than 0:6.4.2-alt4"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |