Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 2 |
CVE-ID | CVE-2023-37369 CVE-2023-38197 |
CWE-ID | CWE-119 CWE-835 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Anolis OS Operating systems & Components / Operating system qt5-srpm-macros Operating systems & Components / Operating system package or component qt5-rpm-macros Operating systems & Components / Operating system package or component qt5-qttranslations Operating systems & Components / Operating system package or component qt5-qttools-common Operating systems & Components / Operating system package or component qt5-qtdoc Operating systems & Components / Operating system package or component qt5-qtbase-common Operating systems & Components / Operating system package or component qt5-devel Operating systems & Components / Operating system package or component qt5 Operating systems & Components / Operating system package or component python3-qt5-doc Operating systems & Components / Operating system package or component python3-qt5-base Operating systems & Components / Operating system package or component python3-qt5 Operating systems & Components / Operating system package or component python-qt5-rpm-macros Operating systems & Components / Operating system package or component qt5-qtxmlpatterns-examples Operating systems & Components / Operating system package or component qt5-qtxmlpatterns-devel Operating systems & Components / Operating system package or component qt5-qtxmlpatterns Operating systems & Components / Operating system package or component qt5-qtx11extras-devel Operating systems & Components / Operating system package or component qt5-qtx11extras Operating systems & Components / Operating system package or component qt5-qtwebsockets-examples Operating systems & Components / Operating system package or component qt5-qtwebsockets-devel Operating systems & Components / Operating system package or component qt5-qtwebsockets Operating systems & Components / Operating system package or component qt5-qtwebkit-devel Operating systems & Components / Operating system package or component qt5-qtwebkit Operating systems & Components / Operating system package or component qt5-qtwebchannel-examples Operating systems & Components / Operating system package or component qt5-qtwebchannel-devel Operating systems & Components / Operating system package or component qt5-qtwebchannel Operating systems & Components / Operating system package or component qt5-qtwayland-examples Operating systems & Components / Operating system package or component qt5-qtwayland-devel Operating systems & Components / Operating system package or component qt5-qtwayland Operating systems & Components / Operating system package or component qt5-qttools-static Operating systems & Components / Operating system package or component qt5-qttools-libs-help Operating systems & Components / Operating system package or component qt5-qttools-libs-designercomponents Operating systems & Components / Operating system package or component qt5-qttools-libs-designer Operating systems & Components / Operating system package or component qt5-qttools-examples Operating systems & Components / Operating system package or component qt5-qttools-devel Operating systems & Components / Operating system package or component qt5-qttools Operating systems & Components / Operating system package or component qt5-qtsvg-examples Operating systems & Components / Operating system package or component qt5-qtsvg-devel Operating systems & Components / Operating system package or component qt5-qtsvg Operating systems & Components / Operating system package or component qt5-qtserialport-examples Operating systems & Components / Operating system package or component qt5-qtserialport-devel Operating systems & Components / Operating system package or component qt5-qtserialport Operating systems & Components / Operating system package or component qt5-qtserialbus-examples Operating systems & Components / Operating system package or component qt5-qtserialbus-devel Operating systems & Components / Operating system package or component qt5-qtserialbus Operating systems & Components / Operating system package or component qt5-qtsensors-examples Operating systems & Components / Operating system package or component qt5-qtsensors-devel Operating systems & Components / Operating system package or component qt5-qtsensors Operating systems & Components / Operating system package or component qt5-qtscript-examples Operating systems & Components / Operating system package or component qt5-qtscript-devel Operating systems & Components / Operating system package or component qt5-qtscript Operating systems & Components / Operating system package or component qt5-qtremoteobjects-examples Operating systems & Components / Operating system package or component qt5-qtremoteobjects-devel Operating systems & Components / Operating system package or component qt5-qtremoteobjects Operating systems & Components / Operating system package or component qt5-qtquickcontrols2-examples Operating systems & Components / Operating system package or component qt5-qtquickcontrols2-devel Operating systems & Components / Operating system package or component qt5-qtquickcontrols2 Operating systems & Components / Operating system package or component qt5-qtquickcontrols-examples Operating systems & Components / Operating system package or component qt5-qtquickcontrols Operating systems & Components / Operating system package or component qt5-qtquick3d-examples Operating systems & Components / Operating system package or component qt5-qtquick3d-devel Operating systems & Components / Operating system package or component qt5-qtquick3d Operating systems & Components / Operating system package or component qt5-qtmultimedia-examples Operating systems & Components / Operating system package or component qt5-qtmultimedia-devel Operating systems & Components / Operating system package or component qt5-qtmultimedia Operating systems & Components / Operating system package or component qt5-qtlocation-examples Operating systems & Components / Operating system package or component qt5-qtlocation-devel Operating systems & Components / Operating system package or component qt5-qtlocation Operating systems & Components / Operating system package or component qt5-qtimageformats Operating systems & Components / Operating system package or component qt5-qtgraphicaleffects Operating systems & Components / Operating system package or component qt5-qtdeclarative-static Operating systems & Components / Operating system package or component qt5-qtdeclarative-examples Operating systems & Components / Operating system package or component qt5-qtdeclarative-devel Operating systems & Components / Operating system package or component qt5-qtdeclarative Operating systems & Components / Operating system package or component qt5-qtconnectivity-examples Operating systems & Components / Operating system package or component qt5-qtconnectivity-doc Operating systems & Components / Operating system package or component qt5-qtconnectivity-devel Operating systems & Components / Operating system package or component qt5-qtconnectivity Operating systems & Components / Operating system package or component qt5-qtbase-static Operating systems & Components / Operating system package or component qt5-qtbase-private-devel Operating systems & Components / Operating system package or component qt5-qtbase-postgresql Operating systems & Components / Operating system package or component qt5-qtbase-odbc Operating systems & Components / Operating system package or component qt5-qtbase-mysql Operating systems & Components / Operating system package or component qt5-qtbase-gui Operating systems & Components / Operating system package or component qt5-qtbase-examples Operating systems & Components / Operating system package or component qt5-qtbase-devel Operating systems & Components / Operating system package or component qt5-qtbase Operating systems & Components / Operating system package or component qt5-qt3d-examples Operating systems & Components / Operating system package or component qt5-qt3d-devel Operating systems & Components / Operating system package or component qt5-qt3d Operating systems & Components / Operating system package or component qt5-qdbusviewer Operating systems & Components / Operating system package or component qt5-linguist Operating systems & Components / Operating system package or component qt5-doctools Operating systems & Components / Operating system package or component qt5-designer Operating systems & Components / Operating system package or component qt5-assistant Operating systems & Components / Operating system package or component python3-qt5-xmlpatterns Operating systems & Components / Operating system package or component python3-qt5-xml Operating systems & Components / Operating system package or component python3-qt5-x11extras Operating systems & Components / Operating system package or component python3-qt5-widgets Operating systems & Components / Operating system package or component python3-qt5-websockets Operating systems & Components / Operating system package or component python3-qt5-webkitwidgets Operating systems & Components / Operating system package or component python3-qt5-webkit Operating systems & Components / Operating system package or component python3-qt5-webchannel Operating systems & Components / Operating system package or component python3-qt5-tools Operating systems & Components / Operating system package or component python3-qt5-test Operating systems & Components / Operating system package or component python3-qt5-svg Operating systems & Components / Operating system package or component python3-qt5-sql Operating systems & Components / Operating system package or component python3-qt5-serialport Operating systems & Components / Operating system package or component python3-qt5-sensors Operating systems & Components / Operating system package or component python3-qt5-remoteobjects Operating systems & Components / Operating system package or component python3-qt5-quickwidgets Operating systems & Components / Operating system package or component python3-qt5-quick3d Operating systems & Components / Operating system package or component python3-qt5-quick Operating systems & Components / Operating system package or component python3-qt5-qml Operating systems & Components / Operating system package or component python3-qt5-printsupport Operating systems & Components / Operating system package or component python3-qt5-positioning Operating systems & Components / Operating system package or component python3-qt5-opengl Operating systems & Components / Operating system package or component python3-qt5-nfc Operating systems & Components / Operating system package or component python3-qt5-network Operating systems & Components / Operating system package or component python3-qt5-multimediawidgets Operating systems & Components / Operating system package or component python3-qt5-multimedia Operating systems & Components / Operating system package or component python3-qt5-location Operating systems & Components / Operating system package or component python3-qt5-help Operating systems & Components / Operating system package or component python3-qt5-gui Operating systems & Components / Operating system package or component python3-qt5-devel Operating systems & Components / Operating system package or component python3-qt5-designer Operating systems & Components / Operating system package or component python3-qt5-dbus Operating systems & Components / Operating system package or component python3-qt5-core Operating systems & Components / Operating system package or component python3-qt5-bluetooth Operating systems & Components / Operating system package or component |
Vendor | OpenAnolis |
Security Bulletin
This security bulletin contains information about 2 vulnerabilities.
EUVDB-ID: #VU79632
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-37369
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing XML content in QXmlStreamReader. A remote attacker can pass specially crafted XML input to the application, trigger memory corruption and perform a denial of service (DoS) attack.
Install updates from vendor's repository.
Vulnerable software versionsAnolis OS: 23
qt5-srpm-macros: before 5.15.11-1
qt5-rpm-macros: before 5.15.11-1
qt5-qttranslations: before 5.15.11-1
qt5-qttools-common: before 5.15.11-1
qt5-qtdoc: before 5.15.11-1
qt5-qtbase-common: before 5.15.11-1
qt5-devel: before 5.15.11-1
qt5: before 5.15.11-1
python3-qt5-doc: before 5.15.10-1
python3-qt5-base: before 5.15.10-1
python3-qt5: before 5.15.10-1
python-qt5-rpm-macros: before 5.15.10-1
qt5-qtxmlpatterns-examples: before 5.15.11-1
qt5-qtxmlpatterns-devel: before 5.15.11-1
qt5-qtxmlpatterns: before 5.15.11-1
qt5-qtx11extras-devel: before 5.15.11-1
qt5-qtx11extras: before 5.15.11-1
qt5-qtwebsockets-examples: before 5.15.11-1
qt5-qtwebsockets-devel: before 5.15.11-1
qt5-qtwebsockets: before 5.15.11-1
qt5-qtwebkit-devel: before 5.212.0-9.alpha4
qt5-qtwebkit: before 5.212.0-9.alpha4
qt5-qtwebchannel-examples: before 5.15.11-1
qt5-qtwebchannel-devel: before 5.15.11-1
qt5-qtwebchannel: before 5.15.11-1
qt5-qtwayland-examples: before 5.15.11-1
qt5-qtwayland-devel: before 5.15.11-1
qt5-qtwayland: before 5.15.11-1
qt5-qttools-static: before 5.15.11-1
qt5-qttools-libs-help: before 5.15.11-1
qt5-qttools-libs-designercomponents: before 5.15.11-1
qt5-qttools-libs-designer: before 5.15.11-1
qt5-qttools-examples: before 5.15.11-1
qt5-qttools-devel: before 5.15.11-1
qt5-qttools: before 5.15.11-1
qt5-qtsvg-examples: before 5.15.11-1
qt5-qtsvg-devel: before 5.15.11-1
qt5-qtsvg: before 5.15.11-1
qt5-qtserialport-examples: before 5.15.11-1
qt5-qtserialport-devel: before 5.15.11-1
qt5-qtserialport: before 5.15.11-1
qt5-qtserialbus-examples: before 5.15.11-1
qt5-qtserialbus-devel: before 5.15.11-1
qt5-qtserialbus: before 5.15.11-1
qt5-qtsensors-examples: before 5.15.11-1
qt5-qtsensors-devel: before 5.15.11-1
qt5-qtsensors: before 5.15.11-1
qt5-qtscript-examples: before 5.15.11-1
qt5-qtscript-devel: before 5.15.11-1
qt5-qtscript: before 5.15.11-1
qt5-qtremoteobjects-examples: before 5.15.11-1
qt5-qtremoteobjects-devel: before 5.15.11-1
qt5-qtremoteobjects: before 5.15.11-1
qt5-qtquickcontrols2-examples: before 5.15.11-1
qt5-qtquickcontrols2-devel: before 5.15.11-1
qt5-qtquickcontrols2: before 5.15.11-1
qt5-qtquickcontrols-examples: before 5.15.11-1
qt5-qtquickcontrols: before 5.15.11-1
qt5-qtquick3d-examples: before 5.15.11-1
qt5-qtquick3d-devel: before 5.15.11-1
qt5-qtquick3d: before 5.15.11-1
qt5-qtmultimedia-examples: before 5.15.11-1
qt5-qtmultimedia-devel: before 5.15.11-1
qt5-qtmultimedia: before 5.15.11-1
qt5-qtlocation-examples: before 5.15.11-1
qt5-qtlocation-devel: before 5.15.11-1
qt5-qtlocation: before 5.15.11-1
qt5-qtimageformats: before 5.15.11-1
qt5-qtgraphicaleffects: before 5.15.11-1
qt5-qtdeclarative-static: before 5.15.11-1
qt5-qtdeclarative-examples: before 5.15.11-1
qt5-qtdeclarative-devel: before 5.15.11-1
qt5-qtdeclarative: before 5.15.11-1
qt5-qtconnectivity-examples: before 5.15.11-1
qt5-qtconnectivity-doc: before 5.15.11-1
qt5-qtconnectivity-devel: before 5.15.11-1
qt5-qtconnectivity: before 5.15.11-1
qt5-qtbase-static: before 5.15.11-1
qt5-qtbase-private-devel: before 5.15.11-1
qt5-qtbase-postgresql: before 5.15.11-1
qt5-qtbase-odbc: before 5.15.11-1
qt5-qtbase-mysql: before 5.15.11-1
qt5-qtbase-gui: before 5.15.11-1
qt5-qtbase-examples: before 5.15.11-1
qt5-qtbase-devel: before 5.15.11-1
qt5-qtbase: before 5.15.11-1
qt5-qt3d-examples: before 5.15.11-1
qt5-qt3d-devel: before 5.15.11-1
qt5-qt3d: before 5.15.11-1
qt5-qdbusviewer: before 5.15.11-1
qt5-linguist: before 5.15.11-1
qt5-doctools: before 5.15.11-1
qt5-designer: before 5.15.11-1
qt5-assistant: before 5.15.11-1
python3-qt5-xmlpatterns: before 5.15.10-1
python3-qt5-xml: before 5.15.10-1
python3-qt5-x11extras: before 5.15.10-1
python3-qt5-widgets: before 5.15.10-1
python3-qt5-websockets: before 5.15.10-1
python3-qt5-webkitwidgets: before 5.15.10-1
python3-qt5-webkit: before 5.15.10-1
python3-qt5-webchannel: before 5.15.10-1
python3-qt5-tools: before 5.15.10-1
python3-qt5-test: before 5.15.10-1
python3-qt5-svg: before 5.15.10-1
python3-qt5-sql: before 5.15.10-1
python3-qt5-serialport: before 5.15.10-1
python3-qt5-sensors: before 5.15.10-1
python3-qt5-remoteobjects: before 5.15.10-1
python3-qt5-quickwidgets: before 5.15.10-1
python3-qt5-quick3d: before 5.15.10-1
python3-qt5-quick: before 5.15.10-1
python3-qt5-qml: before 5.15.10-1
python3-qt5-printsupport: before 5.15.10-1
python3-qt5-positioning: before 5.15.10-1
python3-qt5-opengl: before 5.15.10-1
python3-qt5-nfc: before 5.15.10-1
python3-qt5-network: before 5.15.10-1
python3-qt5-multimediawidgets: before 5.15.10-1
python3-qt5-multimedia: before 5.15.10-1
python3-qt5-location: before 5.15.10-1
python3-qt5-help: before 5.15.10-1
python3-qt5-gui: before 5.15.10-1
python3-qt5-devel: before 5.15.10-1
python3-qt5-designer: before 5.15.10-1
python3-qt5-dbus: before 5.15.10-1
python3-qt5-core: before 5.15.10-1
python3-qt5-bluetooth: before 5.15.10-1
CPE2.3https://anas.openanolis.cn/errata/detail/ANSA-2023:0929
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU78697
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-38197
CWE-ID:
CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when handling recursive expansions. A remote attacker can consume all available system resources and cause denial of service conditions.
MitigationInstall updates from vendor's repository.
Vulnerable software versionsAnolis OS: 23
qt5-srpm-macros: before 5.15.11-1
qt5-rpm-macros: before 5.15.11-1
qt5-qttranslations: before 5.15.11-1
qt5-qttools-common: before 5.15.11-1
qt5-qtdoc: before 5.15.11-1
qt5-qtbase-common: before 5.15.11-1
qt5-devel: before 5.15.11-1
qt5: before 5.15.11-1
python3-qt5-doc: before 5.15.10-1
python3-qt5-base: before 5.15.10-1
python3-qt5: before 5.15.10-1
python-qt5-rpm-macros: before 5.15.10-1
qt5-qtxmlpatterns-examples: before 5.15.11-1
qt5-qtxmlpatterns-devel: before 5.15.11-1
qt5-qtxmlpatterns: before 5.15.11-1
qt5-qtx11extras-devel: before 5.15.11-1
qt5-qtx11extras: before 5.15.11-1
qt5-qtwebsockets-examples: before 5.15.11-1
qt5-qtwebsockets-devel: before 5.15.11-1
qt5-qtwebsockets: before 5.15.11-1
qt5-qtwebkit-devel: before 5.212.0-9.alpha4
qt5-qtwebkit: before 5.212.0-9.alpha4
qt5-qtwebchannel-examples: before 5.15.11-1
qt5-qtwebchannel-devel: before 5.15.11-1
qt5-qtwebchannel: before 5.15.11-1
qt5-qtwayland-examples: before 5.15.11-1
qt5-qtwayland-devel: before 5.15.11-1
qt5-qtwayland: before 5.15.11-1
qt5-qttools-static: before 5.15.11-1
qt5-qttools-libs-help: before 5.15.11-1
qt5-qttools-libs-designercomponents: before 5.15.11-1
qt5-qttools-libs-designer: before 5.15.11-1
qt5-qttools-examples: before 5.15.11-1
qt5-qttools-devel: before 5.15.11-1
qt5-qttools: before 5.15.11-1
qt5-qtsvg-examples: before 5.15.11-1
qt5-qtsvg-devel: before 5.15.11-1
qt5-qtsvg: before 5.15.11-1
qt5-qtserialport-examples: before 5.15.11-1
qt5-qtserialport-devel: before 5.15.11-1
qt5-qtserialport: before 5.15.11-1
qt5-qtserialbus-examples: before 5.15.11-1
qt5-qtserialbus-devel: before 5.15.11-1
qt5-qtserialbus: before 5.15.11-1
qt5-qtsensors-examples: before 5.15.11-1
qt5-qtsensors-devel: before 5.15.11-1
qt5-qtsensors: before 5.15.11-1
qt5-qtscript-examples: before 5.15.11-1
qt5-qtscript-devel: before 5.15.11-1
qt5-qtscript: before 5.15.11-1
qt5-qtremoteobjects-examples: before 5.15.11-1
qt5-qtremoteobjects-devel: before 5.15.11-1
qt5-qtremoteobjects: before 5.15.11-1
qt5-qtquickcontrols2-examples: before 5.15.11-1
qt5-qtquickcontrols2-devel: before 5.15.11-1
qt5-qtquickcontrols2: before 5.15.11-1
qt5-qtquickcontrols-examples: before 5.15.11-1
qt5-qtquickcontrols: before 5.15.11-1
qt5-qtquick3d-examples: before 5.15.11-1
qt5-qtquick3d-devel: before 5.15.11-1
qt5-qtquick3d: before 5.15.11-1
qt5-qtmultimedia-examples: before 5.15.11-1
qt5-qtmultimedia-devel: before 5.15.11-1
qt5-qtmultimedia: before 5.15.11-1
qt5-qtlocation-examples: before 5.15.11-1
qt5-qtlocation-devel: before 5.15.11-1
qt5-qtlocation: before 5.15.11-1
qt5-qtimageformats: before 5.15.11-1
qt5-qtgraphicaleffects: before 5.15.11-1
qt5-qtdeclarative-static: before 5.15.11-1
qt5-qtdeclarative-examples: before 5.15.11-1
qt5-qtdeclarative-devel: before 5.15.11-1
qt5-qtdeclarative: before 5.15.11-1
qt5-qtconnectivity-examples: before 5.15.11-1
qt5-qtconnectivity-doc: before 5.15.11-1
qt5-qtconnectivity-devel: before 5.15.11-1
qt5-qtconnectivity: before 5.15.11-1
qt5-qtbase-static: before 5.15.11-1
qt5-qtbase-private-devel: before 5.15.11-1
qt5-qtbase-postgresql: before 5.15.11-1
qt5-qtbase-odbc: before 5.15.11-1
qt5-qtbase-mysql: before 5.15.11-1
qt5-qtbase-gui: before 5.15.11-1
qt5-qtbase-examples: before 5.15.11-1
qt5-qtbase-devel: before 5.15.11-1
qt5-qtbase: before 5.15.11-1
qt5-qt3d-examples: before 5.15.11-1
qt5-qt3d-devel: before 5.15.11-1
qt5-qt3d: before 5.15.11-1
qt5-qdbusviewer: before 5.15.11-1
qt5-linguist: before 5.15.11-1
qt5-doctools: before 5.15.11-1
qt5-designer: before 5.15.11-1
qt5-assistant: before 5.15.11-1
python3-qt5-xmlpatterns: before 5.15.10-1
python3-qt5-xml: before 5.15.10-1
python3-qt5-x11extras: before 5.15.10-1
python3-qt5-widgets: before 5.15.10-1
python3-qt5-websockets: before 5.15.10-1
python3-qt5-webkitwidgets: before 5.15.10-1
python3-qt5-webkit: before 5.15.10-1
python3-qt5-webchannel: before 5.15.10-1
python3-qt5-tools: before 5.15.10-1
python3-qt5-test: before 5.15.10-1
python3-qt5-svg: before 5.15.10-1
python3-qt5-sql: before 5.15.10-1
python3-qt5-serialport: before 5.15.10-1
python3-qt5-sensors: before 5.15.10-1
python3-qt5-remoteobjects: before 5.15.10-1
python3-qt5-quickwidgets: before 5.15.10-1
python3-qt5-quick3d: before 5.15.10-1
python3-qt5-quick: before 5.15.10-1
python3-qt5-qml: before 5.15.10-1
python3-qt5-printsupport: before 5.15.10-1
python3-qt5-positioning: before 5.15.10-1
python3-qt5-opengl: before 5.15.10-1
python3-qt5-nfc: before 5.15.10-1
python3-qt5-network: before 5.15.10-1
python3-qt5-multimediawidgets: before 5.15.10-1
python3-qt5-multimedia: before 5.15.10-1
python3-qt5-location: before 5.15.10-1
python3-qt5-help: before 5.15.10-1
python3-qt5-gui: before 5.15.10-1
python3-qt5-devel: before 5.15.10-1
python3-qt5-designer: before 5.15.10-1
python3-qt5-dbus: before 5.15.10-1
python3-qt5-core: before 5.15.10-1
python3-qt5-bluetooth: before 5.15.10-1
CPE2.3https://anas.openanolis.cn/errata/detail/ANSA-2023:0929
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.