|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-25580: libqt5-qtbase,qt6-base: qtbase: potential buffer overflow when reading KTX images | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | SMASH SMASH <smash_bz> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | andrea.mattiazzo, fvogt, stoyan.manolov |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/394279/ | ||
| Whiteboard: | CVSSv3.1:SUSE:CVE-2024-25580:6.2:(AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) | ||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
SMASH SMASH
2024-02-16 08:43:01 UTC
KTX support got introduced in Qt 5.12, so qt3 and libqt4 are not affected. Patch: https://github.com/qt/qtbase/commit/28ecb523ce8490bff38b251b3df703c72e057519 6.6 - https://ftp.fau.de/qtproject/archive/qt/6.6/CVE-2024-25580-qtbase-6.6.diff 6.5 - https://ftp.fau.de/qtproject/archive/qt/6.5/CVE-2024-25580-qtbase-6.5.diff 6.2 - https://ftp.fau.de/qtproject/archive/qt/6.2/CVE-2024-25580-qtbase-6.2.diff 5.15 - https://ftp.fau.de/qtproject/archive/qt/5.15/CVE-2024-25580-qtbase-5.15.diff Thanks Fabian, tracking as affected: - SUSE:ALP:Source:Standard:1.0/libqt5-qtbase - SUSE:SLE-15-SP2:Update/libqt5-qtbase - SUSE:SLE-15-SP4:Update/libqt5-qtbase - SUSE:SLE-15-SP5:Update/libqt5-qtbase - SUSE:SLE-15-SP5:Update/qt6-base - SUSE:ALP:Source:Standard:1.0/qt6-base - openSUSE:Factory/qt6-base - openSUSE:Factory/libqt5-qtbase (In reply to Andrea Mattiazzo from comment #2) > Thanks Fabian, tracking as affected: > - openSUSE:Factory/qt6-base The Qt6 packages were updated to 6.6.2 and are not affected anymore |