vulnerability

Amazon Linux AMI 2: CVE-2023-37369: Security patch for qt5-qtbase (ALAS-2024-2533)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
08/20/2023
Added
05/01/2024
Modified
01/28/2025

Description

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

Solution(s)

amazon-linux-ami-2-upgrade-qt5-qtbaseamazon-linux-ami-2-upgrade-qt5-qtbase-commonamazon-linux-ami-2-upgrade-qt5-qtbase-debuginfoamazon-linux-ami-2-upgrade-qt5-qtbase-develamazon-linux-ami-2-upgrade-qt5-qtbase-docamazon-linux-ami-2-upgrade-qt5-qtbase-examplesamazon-linux-ami-2-upgrade-qt5-qtbase-guiamazon-linux-ami-2-upgrade-qt5-qtbase-mysqlamazon-linux-ami-2-upgrade-qt5-qtbase-odbcamazon-linux-ami-2-upgrade-qt5-qtbase-postgresqlamazon-linux-ami-2-upgrade-qt5-qtbase-staticamazon-linux-ami-2-upgrade-qt5-rpm-macros
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.