Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Qt | Qt | 5.5.0 (including) | 5.12.8 (excluding) |
| Red Hat Enterprise Linux 8 | RedHat | qt5-qtbase-0:5.12.5-6.el8 | * |
| Red Hat Enterprise Linux 8 | RedHat | qt5-qttools-0:5.12.5-2.el8 | * |
| Red Hat Enterprise Linux 8 | RedHat | qt5-qtwebsockets-0:5.12.5-2.el8 | * |
| Phantomjs | Ubuntu | bionic | * |
| Phantomjs | Ubuntu | eoan | * |
| Phantomjs | Ubuntu | esm-apps/bionic | * |
| Phantomjs | Ubuntu | esm-apps/focal | * |
| Phantomjs | Ubuntu | esm-apps/xenial | * |
| Phantomjs | Ubuntu | focal | * |
| Phantomjs | Ubuntu | trusty | * |
| Phantomjs | Ubuntu | xenial | * |
| Pyside | Ubuntu | bionic | * |
| Pyside | Ubuntu | eoan | * |
| Pyside | Ubuntu | esm-apps/bionic | * |
| Pyside | Ubuntu | esm-apps/xenial | * |
| Pyside | Ubuntu | esm-infra-legacy/trusty | * |
| Pyside | Ubuntu | trusty | * |
| Pyside | Ubuntu | trusty/esm | * |
| Pyside | Ubuntu | xenial | * |
| Pyside2 | Ubuntu | devel | * |
| Pyside2 | Ubuntu | eoan | * |
| Pyside2 | Ubuntu | esm-apps/focal | * |
| Pyside2 | Ubuntu | esm-apps/jammy | * |
| Pyside2 | Ubuntu | esm-apps/noble | * |
| Pyside2 | Ubuntu | focal | * |
| Pyside2 | Ubuntu | groovy | * |
| Pyside2 | Ubuntu | hirsute | * |
| Pyside2 | Ubuntu | impish | * |
| Pyside2 | Ubuntu | jammy | * |
| Pyside2 | Ubuntu | kinetic | * |
| Pyside2 | Ubuntu | lunar | * |
| Pyside2 | Ubuntu | mantic | * |
| Pyside2 | Ubuntu | noble | * |
| Pyside2 | Ubuntu | oracular | * |
| Pyside2 | Ubuntu | plucky | * |
| Pyside2 | Ubuntu | questing | * |
| Pyside2 | Ubuntu | trusty | * |
| Qt4-x11 | Ubuntu | bionic | * |
| Qt4-x11 | Ubuntu | eoan | * |
| Qt4-x11 | Ubuntu | esm-apps/bionic | * |
| Qt4-x11 | Ubuntu | esm-infra-legacy/trusty | * |
| Qt4-x11 | Ubuntu | esm-infra/xenial | * |
| Qt4-x11 | Ubuntu | trusty | * |
| Qt4-x11 | Ubuntu | trusty/esm | * |
| Qt4-x11 | Ubuntu | xenial | * |
| Qtbase-opensource-src | Ubuntu | bionic | * |
| Qtbase-opensource-src | Ubuntu | eoan | * |
| Qtbase-opensource-src | Ubuntu | esm-infra/bionic | * |
| Qtbase-opensource-src | Ubuntu | esm-infra/xenial | * |
| Qtbase-opensource-src | Ubuntu | trusty | * |
| Qtbase-opensource-src | Ubuntu | xenial | * |