- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202312-07
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: QtWebEngine: Multiple Vulnerabilities
     Date: December 22, 2023
     Bugs: #913050, #915465
       ID: 202312-07

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilitiies have been discovered in QtWebEngine, the worst
of which could lead to remote code execution.

Background
==========

QtWebEngine is a library for rendering dynamic web content in Qt5 and
Qt6 C++ and QML applications.

Affected packages
=================

Package             Vulnerable           Unaffected
------------------  -------------------  --------------------
dev-qt/qtwebengine  < 5.15.11_p20231120  >= 5.15.11_p20231120

Description
===========

Multiple vulnerabilities have been discovered in QtWebEngine. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All QtWebEngine users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-qt/qtwebengine-5.15.11_p20231120"

References
==========

[ 1 ] CVE-2023-4068
      https://nvd.nist.gov/vuln/detail/CVE-2023-4068
[ 2 ] CVE-2023-4069
      https://nvd.nist.gov/vuln/detail/CVE-2023-4069
[ 3 ] CVE-2023-4070
      https://nvd.nist.gov/vuln/detail/CVE-2023-4070
[ 4 ] CVE-2023-4071
      https://nvd.nist.gov/vuln/detail/CVE-2023-4071
[ 5 ] CVE-2023-4072
      https://nvd.nist.gov/vuln/detail/CVE-2023-4072
[ 6 ] CVE-2023-4073
      https://nvd.nist.gov/vuln/detail/CVE-2023-4073
[ 7 ] CVE-2023-4074
      https://nvd.nist.gov/vuln/detail/CVE-2023-4074
[ 8 ] CVE-2023-4075
      https://nvd.nist.gov/vuln/detail/CVE-2023-4075
[ 9 ] CVE-2023-4076
      https://nvd.nist.gov/vuln/detail/CVE-2023-4076
[ 10 ] CVE-2023-4077
      https://nvd.nist.gov/vuln/detail/CVE-2023-4077
[ 11 ] CVE-2023-4078
      https://nvd.nist.gov/vuln/detail/CVE-2023-4078
[ 12 ] CVE-2023-4761
      https://nvd.nist.gov/vuln/detail/CVE-2023-4761
[ 13 ] CVE-2023-4762
      https://nvd.nist.gov/vuln/detail/CVE-2023-4762
[ 14 ] CVE-2023-4763
      https://nvd.nist.gov/vuln/detail/CVE-2023-4763
[ 15 ] CVE-2023-4764
      https://nvd.nist.gov/vuln/detail/CVE-2023-4764
[ 16 ] CVE-2023-5218
      https://nvd.nist.gov/vuln/detail/CVE-2023-5218
[ 17 ] CVE-2023-5473
      https://nvd.nist.gov/vuln/detail/CVE-2023-5473
[ 18 ] CVE-2023-5474
      https://nvd.nist.gov/vuln/detail/CVE-2023-5474
[ 19 ] CVE-2023-5475
      https://nvd.nist.gov/vuln/detail/CVE-2023-5475
[ 20 ] CVE-2023-5476
      https://nvd.nist.gov/vuln/detail/CVE-2023-5476
[ 21 ] CVE-2023-5477
      https://nvd.nist.gov/vuln/detail/CVE-2023-5477
[ 22 ] CVE-2023-5478
      https://nvd.nist.gov/vuln/detail/CVE-2023-5478
[ 23 ] CVE-2023-5479
      https://nvd.nist.gov/vuln/detail/CVE-2023-5479
[ 24 ] CVE-2023-5480
      https://nvd.nist.gov/vuln/detail/CVE-2023-5480
[ 25 ] CVE-2023-5481
      https://nvd.nist.gov/vuln/detail/CVE-2023-5481
[ 26 ] CVE-2023-5482
      https://nvd.nist.gov/vuln/detail/CVE-2023-5482
[ 27 ] CVE-2023-5483
      https://nvd.nist.gov/vuln/detail/CVE-2023-5483
[ 28 ] CVE-2023-5484
      https://nvd.nist.gov/vuln/detail/CVE-2023-5484
[ 29 ] CVE-2023-5485
      https://nvd.nist.gov/vuln/detail/CVE-2023-5485
[ 30 ] CVE-2023-5486
      https://nvd.nist.gov/vuln/detail/CVE-2023-5486
[ 31 ] CVE-2023-5487
      https://nvd.nist.gov/vuln/detail/CVE-2023-5487
[ 32 ] CVE-2023-5849
      https://nvd.nist.gov/vuln/detail/CVE-2023-5849
[ 33 ] CVE-2023-5850
      https://nvd.nist.gov/vuln/detail/CVE-2023-5850
[ 34 ] CVE-2023-5851
      https://nvd.nist.gov/vuln/detail/CVE-2023-5851
[ 35 ] CVE-2023-5852
      https://nvd.nist.gov/vuln/detail/CVE-2023-5852
[ 36 ] CVE-2023-5853
      https://nvd.nist.gov/vuln/detail/CVE-2023-5853
[ 37 ] CVE-2023-5854
      https://nvd.nist.gov/vuln/detail/CVE-2023-5854
[ 38 ] CVE-2023-5855
      https://nvd.nist.gov/vuln/detail/CVE-2023-5855
[ 39 ] CVE-2023-5856
      https://nvd.nist.gov/vuln/detail/CVE-2023-5856
[ 40 ] CVE-2023-5857
      https://nvd.nist.gov/vuln/detail/CVE-2023-5857
[ 41 ] CVE-2023-5858
      https://nvd.nist.gov/vuln/detail/CVE-2023-5858
[ 42 ] CVE-2023-5859
      https://nvd.nist.gov/vuln/detail/CVE-2023-5859
[ 43 ] CVE-2023-5996
      https://nvd.nist.gov/vuln/detail/CVE-2023-5996
[ 44 ] CVE-2023-5997
      https://nvd.nist.gov/vuln/detail/CVE-2023-5997
[ 45 ] CVE-2023-6112
      https://nvd.nist.gov/vuln/detail/CVE-2023-6112

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202312-07

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2023 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5/

Gentoo: GLSA-202312-07: QtWebEngine: Multiple Vulnerabilities

Multiple vulnerabilitiies have been discovered in QtWebEngine, the worst of which could lead to remote code execution.

Summary

Multiple vulnerabilities have been discovered in QtWebEngine. Please review the CVE identifiers referenced below for details.

Resolution

All QtWebEngine users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-qt/qtwebengine-5.15.11_p20231120"

References

[ 1 ] CVE-2023-4068 https://nvd.nist.gov/vuln/detail/CVE-2023-4068 [ 2 ] CVE-2023-4069 https://nvd.nist.gov/vuln/detail/CVE-2023-4069 [ 3 ] CVE-2023-4070 https://nvd.nist.gov/vuln/detail/CVE-2023-4070 [ 4 ] CVE-2023-4071 https://nvd.nist.gov/vuln/detail/CVE-2023-4071 [ 5 ] CVE-2023-4072 https://nvd.nist.gov/vuln/detail/CVE-2023-4072 [ 6 ] CVE-2023-4073 https://nvd.nist.gov/vuln/detail/CVE-2023-4073 [ 7 ] CVE-2023-4074 https://nvd.nist.gov/vuln/detail/CVE-2023-4074 [ 8 ] CVE-2023-4075 https://nvd.nist.gov/vuln/detail/CVE-2023-4075 [ 9 ] CVE-2023-4076 https://nvd.nist.gov/vuln/detail/CVE-2023-4076 [ 10 ] CVE-2023-4077 https://nvd.nist.gov/vuln/detail/CVE-2023-4077 [ 11 ] CVE-2023-4078 https://nvd.nist.gov/vuln/detail/CVE-2023-4078 [ 12 ] CVE-2023-4761 https://nvd.nist.gov/vuln/detail/CVE-2023-4761 [ 13 ] CVE-2023-4762 https://nvd.nist.gov/vuln/detail/CVE-2023-4762 [ 14 ] CVE-2023-4763 https://nvd.nist.gov/vuln/detail/CVE-2023-4763 [ 15 ] CVE-2023-4764 https://nvd.nist.gov/vuln/detail/CVE-2023-4764 [ 16 ] CVE-2023-5218 https://nvd.nist.gov/vuln/detail/CVE-2023-5218 [ 17 ] CVE-2023-5473 https://nvd.nist.gov/vuln/detail/CVE-2023-5473 [ 18 ] CVE-2023-5474 https://nvd.nist.gov/vuln/detail/CVE-2023-5474 [ 19 ] CVE-2023-5475 https://nvd.nist.gov/vuln/detail/CVE-2023-5475 [ 20 ] CVE-2023-5476 https://nvd.nist.gov/vuln/detail/CVE-2023-5476 [ 21 ] CVE-2023-5477 https://nvd.nist.gov/vuln/detail/CVE-2023-5477 [ 22 ] CVE-2023-5478 https://nvd.nist.gov/vuln/detail/CVE-2023-5478 [ 23 ] CVE-2023-5479 https://nvd.nist.gov/vuln/detail/CVE-2023-5479 [ 24 ] CVE-2023-5480 https://nvd.nist.gov/vuln/detail/CVE-2023-5480 [ 25 ] CVE-2023-5481 https://nvd.nist.gov/vuln/detail/CVE-2023-5481 [ 26 ] CVE-2023-5482 https://nvd.nist.gov/vuln/detail/CVE-2023-5482 [ 27 ] CVE-2023-5483 https://nvd.nist.gov/vuln/detail/CVE-2023-5483 [ 28 ] CVE-2023-5484 https://nvd.nist.gov/vuln/detail/CVE-2023-5484 [ 29 ] CVE-2023-5485 https://nvd.nist.gov/vuln/detail/CVE-2023-5485 [ 30 ] CVE-2023-5486 https://nvd.nist.gov/vuln/detail/CVE-2023-5486 [ 31 ] CVE-2023-5487 https://nvd.nist.gov/vuln/detail/CVE-2023-5487 [ 32 ] CVE-2023-5849 https://nvd.nist.gov/vuln/detail/CVE-2023-5849 [ 33 ] CVE-2023-5850 https://nvd.nist.gov/vuln/detail/CVE-2023-5850 [ 34 ] CVE-2023-5851 https://nvd.nist.gov/vuln/detail/CVE-2023-5851 [ 35 ] CVE-2023-5852 https://nvd.nist.gov/vuln/detail/CVE-2023-5852 [ 36 ] CVE-2023-5853 https://nvd.nist.gov/vuln/detail/CVE-2023-5853 [ 37 ] CVE-2023-5854 https://nvd.nist.gov/vuln/detail/CVE-2023-5854 [ 38 ] CVE-2023-5855 https://nvd.nist.gov/vuln/detail/CVE-2023-5855 [ 39 ] CVE-2023-5856 https://nvd.nist.gov/vuln/detail/CVE-2023-5856 [ 40 ] CVE-2023-5857 https://nvd.nist.gov/vuln/detail/CVE-2023-5857 [ 41 ] CVE-2023-5858 https://nvd.nist.gov/vuln/detail/CVE-2023-5858 [ 42 ] CVE-2023-5859 https://nvd.nist.gov/vuln/detail/CVE-2023-5859 [ 43 ] CVE-2023-5996 https://nvd.nist.gov/vuln/detail/CVE-2023-5996 [ 44 ] CVE-2023-5997 https://nvd.nist.gov/vuln/detail/CVE-2023-5997 [ 45 ] CVE-2023-6112 https://nvd.nist.gov/vuln/detail/CVE-2023-6112

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
https://security.gentoo.org/glsa/202312-07

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity
Severity: High
Title: QtWebEngine: Multiple Vulnerabilities
Date: December 22, 2023
Bugs: #913050, #915465
ID: 202312-07

Synopsis

Multiple vulnerabilitiies have been discovered in QtWebEngine, the worst of which could lead to remote code execution.

Background

QtWebEngine is a library for rendering dynamic web content in Qt5 and Qt6 C++ and QML applications.

Affected Packages

Package Vulnerable Unaffected ------------------ ------------------- -------------------- dev-qt/qtwebengine < 5.15.11_p20231120 >= 5.15.11_p20231120

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Related News