CVE-2015-9541
24.01.2020, 22:15
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qt | qt | 5.5.0 ≤ 𝑥 < 5.12.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| phantomjs |
| ||||||||||||||||||||||||||
| pyside |
| ||||||||||||||||||||||||||
| pyside2 |
| ||||||||||||||||||||||||||
| qt4-x11 |
| ||||||||||||||||||||||||||
| qtbase-opensource-src |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| qt5-assistant |
| ||
| qt5-designer |
| ||
| qt5-doctools |
| ||
| qt5-linguist |
| ||
| qt5-qdbusviewer |
| ||
| qt5-qtbase |
| ||
| qt5-qtbase-common |
| ||
| qt5-qtbase-devel |
| ||
| qt5-qtbase-examples |
| ||
| qt5-qtbase-gui |
| ||
| qt5-qtbase-mysql |
| ||
| qt5-qtbase-odbc |
| ||
| qt5-qtbase-postgresql |
| ||
| qt5-qtbase-private-devel |
| ||
| qt5-qtbase-static |
| ||
| qt5-qttools |
| ||
| qt5-qttools-common |
| ||
| qt5-qttools-devel |
| ||
| qt5-qttools-examples |
| ||
| qt5-qttools-libs-designer |
| ||
| qt5-qttools-libs-designercomponents |
| ||
| qt5-qttools-libs-help |
| ||
| qt5-qttools-static |
| ||
| qt5-qtwebsockets |
| ||
| qt5-qtwebsockets-devel |
| ||
| qt5-qtwebsockets-examples |
|
References