Bug 6906 - [Anolis OS 23] Bugfix for CVE-2023-37369
Summary: [Anolis OS 23] Bugfix for CVE-2023-37369
Status: RESOLVED FIXED
Alias: None
Product: Anolis OS 23
Classification: Anolis OS
Component: BaseOS Packages (show other bugs) BaseOS Packages
Version: unspecified
Hardware: All Linux
: P2-High S2-major
Target Milestone: ---
Assignee: happy_orange
QA Contact: bolong_tbl
URL:
Whiteboard:
Keywords: CVE
Depends on:
Blocks:
 
Reported: 2023-10-18 14:18 UTC by 小龙
Modified: 2023-10-18 14:18 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description 小龙 admin 2023-10-18 14:18:40 UTC
Description:
在5.15.15之前的Qt、6.2.9之前的6.x以及6.5.2之前的6.3.x到6.5.x中,QXmlStreamReader中可能会通过精心设计的XML字符串导致应用程序崩溃,从而触发前缀为大于长度。

Broken commit info:

Bugfix commit info:
https://bugzilla.suse.com/attachment.cgi?id=868835
https://bugzilla.suse.com/attachment.cgi?id=868836
https://bugzilla.suse.com/attachment.cgi?id=868834