[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:4690-01 -- Centos qt5-qtbase, qt5-qttools, qt5-qtwebsockets

ID: oval:org.secpod.oval:def:67997Date: (C)2020-12-23   (M)2023-09-20
Class: PATCHFamily: unix




Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt. Security Fix: * qt: XML entity expansion vulnerability * qt5-qtwebsockets: websocket implementation allows only limited size for frames and messages therefore attacker can cause DOS * qt: files placed by attacker can influence the working directory and lead to malicious code execution * qt: files placed by attacker can influence the working directory and lead to malicious code execution * qt5: incorrectly calls SSL_shutdown in OpenSSL mid-handshake causing denial of service in TLS applications For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.3 Release Notes linked from the References section.

Platform:
CentOS 8
Product:
qt5-qtbase
qt5-qttools
qt5-qtwebsockets
Reference:
RHSA-2020:4690-01
CVE-2015-9541
CVE-2018-21035
CVE-2020-0569
CVE-2020-0570
CVE-2020-13962
CVE    5
CVE-2020-0569
CVE-2020-0570
CVE-2020-13962
CVE-2018-21035
...
CPE    4
cpe:/a:qt:qt5-qttools
cpe:/a:qt:qt5-qtbase
cpe:/a:qt:qt5-qtwebsockets
cpe:/o:centos:centos:8
...

© SecPod Technologies