## This update for libqt4 fixes the following issues: * CVE-2021-45930: Fix out of-bounds write when parsing path nodes (bsc#1196654). * CVE-2023-32573: Fix missing initialization of QSvgFont unitsPerEm (bsc#1211298). * CVE-2023-32763: Fix potential buffer when rendering a SVG file with an image inside (bsc#1211798). * CVE-2023-34410: Fix missing sync of disablement of loading root certificates in qsslsocketprivate (bsc#1211994). * CVE-2023-37369: Fix buffer overflow in QXmlStreamReader (bsc#1214327). * CVE-2023-38197: Fix infinite loops in QXmlStreamReader (bsc#1213326). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:
* bsc#1196654
* bsc#1211298
* bsc#1211798
* bsc#1211994
* bsc#1213326
* bsc#1214327
Cross-
* CVE-2021-45930
* CVE-2023-32573
* CVE-2023-32763
* CVE-2023-34410
* CVE-2023-37369
* CVE-2023-38197
CVSS scores:
* CVE-2021-45930 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2021-45930 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-32573 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-32573 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2023-32763 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
* CVE-2023-32763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-34410 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Get the latest Linux and open source security news straight to your inbox.