Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 10: DLA-3539-1 Urgent: qt4-x11 Memory Handling Vulnerabilities

debian lts
Calendar Grey August 22, 2023
Dist Debian Esm H88
Debian LTS Notice DLA-3540-1 highlights multiple vulnerabilities in libjpeg-turbo, urging users to upgrade for enhanced security.
Several vulnerabilities have been found in qt4-x11, a graphical windowing toolkit

Summary

CVE-2021-3481

While rendering and displaying a crafted Scalable Vector Graphics
(SVG) file this flaw may lead to an unauthorized memory access. The
highest threat from this vulnerability is to data confidentiality
and the application availability.

CVE-2021-45930

An out-of-bounds write in
QtPrivate::QCommonArrayOps::growAppend
(called from QPainterPath::addPath and QPathClipper::intersect).

CVE-2023-32573

Uninitialized variable usage in m_unitsPerEm.

CVE-2023-32763

An application crash in QXmlStreamReader via a crafted XML string
that triggers a situation in which a prefix is greater than a
length.

CVE-2023-34410

Certificate validation for TLS does not always consider whether the
root of a chain is a configured CA certificate.

CVE-2023-37369

There can be an application crash in QXmlStreamReader via a crafted
XML string that triggers a situation in which a prefix is greater
than a length.

CVE-2023-38197

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: qt4-x11
Version: 4:4.8.7+dfsg-18+deb10u2
CVE ID: CVE-2021-3481 CVE-2021-45930 CVE-2023-32573 CVE-2023-32763

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here