Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8 MGASA-2023-0190 Moderate: Qtbase5 HSTS Parsing Issue

mageia
Calendar Grey May 31, 2023
Dist Mageia Esm H88
Recent updates for qtbase5 packages address critical security vulnerabilities in Mageia. Significant concerns involve HSTS interpretation and SVG buffer overflow risks.
Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server

Summary

Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match. (CVE-2023-32762) QTextLayout buffer overflow in SVG file rendering. (CVE-2023-32763)

References

- https://bugs.mageia.org/show_bug.cgi?id=31940

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JOTXCTZAIHUV2MKEPOPE3QDWDQRQN7TL/

- https://www.cve.org/CVERecord?id=CVE-2023-32762

- https://www.cve.org/CVERecord?id=CVE-2023-32763

Resolution

SRPMS

- 8/core/qtbase5-5.15.2-4.9.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 31 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0190.html
Type: security
CVE: CVE-2023-32762, CVE-2023-32763

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here