[ GLSA 202405-14 ] QtWebEngine: Multiple Vulnerabilities
[email protected] Sun, 05 May 2024 08:20:37 -0000
| Newsgroups | gmane.linux.gentoo.announce |
|---|---|
| Message-ID | <171489723803.8.558278343662232937@987c7955d8b1> |
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202405-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: QtWebEngine: Multiple Vulnerabilities
Date: May 05, 2024
Bugs: #927746
ID: 202405-14
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been discovered in QtWebEngine, the worst
of which could lead to remote code execution.
Background
==========
QtWebEngine is a library for rendering dynamic web content in Qt5 and
Qt6 C++ and QML applications.
Affected packages
=================
Package Vulnerable Unaffected
------------------ ------------------- --------------------
dev-qt/qtwebengine < 5.15.13_p20240322 >= 5.15.13_p20240322
Description
===========
Multiple vulnerabilities have been discovered in QtWebEngine. Please
review the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All QtWebEngine users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-qt/qtwebengine-5.15.13_p20240322"
References
==========
[ 1 ] CVE-2024-0804
https://nvd.nist.gov/vuln/detail/CVE-2024-0804
[ 2 ] CVE-2024-0805
https://nvd.nist.gov/vuln/detail/CVE-2024-0805
[ 3 ] CVE-2024-0806
https://nvd.nist.gov/vuln/detail/CVE-2024-0806
[ 4 ] CVE-2024-0807
https://nvd.nist.gov/vuln/detail/CVE-2024-0807
[ 5 ] CVE-2024-0808
https://nvd.nist.gov/vuln/detail/CVE-2024-0808
[ 6 ] CVE-2024-0809
https://nvd.nist.gov/vuln/detail/CVE-2024-0809
[ 7 ] CVE-2024-0810
https://nvd.nist.gov/vuln/detail/CVE-2024-0810
[ 8 ] CVE-2024-0811
https://nvd.nist.gov/vuln/detail/CVE-2024-0811
[ 9 ] CVE-2024-0812
https://nvd.nist.gov/vuln/detail/CVE-2024-0812
[ 10 ] CVE-2024-0813
https://nvd.nist.gov/vuln/detail/CVE-2024-0813
[ 11 ] CVE-2024-0814
https://nvd.nist.gov/vuln/detail/CVE-2024-0814
[ 12 ] CVE-2024-1059
https://nvd.nist.gov/vuln/detail/CVE-2024-1059
[ 13 ] CVE-2024-1060
https://nvd.nist.gov/vuln/detail/CVE-2024-1060
[ 14 ] CVE-2024-1077
https://nvd.nist.gov/vuln/detail/CVE-2024-1077
[ 15 ] CVE-2024-1283
https://nvd.nist.gov/vuln/detail/CVE-2024-1283
[ 16 ] CVE-2024-1284
https://nvd.nist.gov/vuln/detail/CVE-2024-1284
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202405-14
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2024 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmY3QVUACgkQFMQkOaVy +9kiMRAAwOSKGujaTi+vphJZwz6Sn3cc6nPvFV+VVb6gJFTaQc1HFTVfzyxiNr+Z WpiviJPdQXC1IChlnohervinEMgrKuqjq2c17wjb6mo2q8lz48iJq14A66lNj2Jp 12/myobLGHR7oovXz1MnxrHDrlF+dMflKT+8TPJaDJauRMfS9BfGMO+c/ogBnvZB ZD9MPAnbXUcZvmJcnw38WTzIehEQ0AAR1EtcnyPpiORCy3nsd84tMY3Kj1gKe0r1 g/aPFpQHLFP7zBFv4zq+sKVIImp347dpExja8yCXTJys06o0nLcgTGKG+yFWjHqo 5fJlCttJ2sk1+7Pw3rkhuNDbm5BLaCC70jT1KASKIGzXS0Cg1MK+MynORsgt9N09 CRETNUpSxTX54OptqIbWugTzYyRi7buV03NbpmQjJQQa71XEBmVmZngOne22aLUT 5dHgX8E6SBdZlS7eBJCR4R63LDmVQnppEzcbICcDmdJ62zydPTZehSX3+PmURbjb s+5MCAM280cG8oQdeds9/VQr5lQmTJF327a9sfK2ibCG6w6QOmW9KnEANtukgbY1 dVPT/oF5Ik9ROsjCDdGynC2NjDC7hcQpaGzPF/rXcRPhMTQirWgQFXxfhpbfBW52 O5NhS/nZP7Ir/ok4RfakqhOgQXAZaCg8QkUu/adajQCd37ZJ07w= =ooEQ -----END PGP SIGNATURE-----