Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1154676

Bug#1041104: qt6-base: CVE-2023-38197

From Lisandro Damián Nicanor Pérez Meyer <perezmeyer@gmail.com>
Newsgroups linux.debian.bugs.dist
Subject Bug#1041104: qt6-base: CVE-2023-38197
Date 2023-07-17 21:40 +0200
Message-ID <GSCeB-Vdk-11@gated-at.bofh.it> (permalink)
References <GRyPL-g8E-19@gated-at.bofh.it> <GSBBT-UKc-1@gated-at.bofh.it> <GSC4V-V9E-5@gated-at.bofh.it> <GRyPL-g8E-19@gated-at.bofh.it> <GSC4V-V9E-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

El lunes, 17 de julio de 2023 16:25:20 -03 Dmitry Shachnev escribió:
> ¡Hola Lisandro!
> 
> On Mon, Jul 17, 2023 at 03:49:13PM -0300, Lisandro Damián Nicanor Pérez Meyer wrote:
> > El viernes, 14 de julio de 2023 18:38:45 -03 Moritz Mühlenhoff escribió:
> > > Source: qt6-base
> > > X-Debbugs-CC: team@security.debian.org
> > > Severity: important
> > > Tags: security
> > >
> > > Hi,
> > >
> > > The following vulnerability was published for qt6-base.
> > >
> > > CVE-2023-38197[0]:
> >
> > I have just tried to backport the cherry-pick of 6.5 to 6.4 but without
> > success. It requires more time and C++ knowledge I have right now I'm afraid
> > :-/
> 
> c216c3d9859a20b3aeec985512e89316423fc3a8 cherry-picks to 6.4 with only one
> conflict, in tst_qxmlstream.cpp. We don't run tests anyway so you could just
> ignore it.
> 
> Anyway, I rebased it and attaching a patch against 6.4 branch.

Problem comes at build time on line 118 on the patch you attached :-/ In fact I needed to add a header to make it work in 6.4.2 :-/

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Bug#1041104: qt6-base: CVE-2023-38197 Moritz Mühlenhoff <jmm@inutil.org> - 2023-07-14 23:50 +0200
  Bug#1041104: qt6-base: CVE-2023-38197   Lisandro Damián Nicanor Pérez Meyer  <perezmeyer@gmail.com> - 2023-07-17 21:00 +0200
    Bug#1041104: qt6-base: CVE-2023-38197 Dmitry Shachnev <mitya57@debian.org> - 2023-07-17 21:30 +0200
      Bug#1041104: qt6-base: CVE-2023-38197   Lisandro Damián Nicanor Pérez Meyer  <perezmeyer@gmail.com> - 2023-07-17 21:40 +0200

csiph-web