Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qt | Qt | 5.5.0 (including) | 5.12.8 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | qt5-qtbase-0:5.12.5-6.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | qt5-qttools-0:5.12.5-2.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | qt5-qtwebsockets-0:5.12.5-2.el8 | * |
Phantomjs | Ubuntu | bionic | * |
Phantomjs | Ubuntu | eoan | * |
Phantomjs | Ubuntu | esm-apps/bionic | * |
Phantomjs | Ubuntu | esm-apps/focal | * |
Phantomjs | Ubuntu | esm-apps/xenial | * |
Phantomjs | Ubuntu | focal | * |
Phantomjs | Ubuntu | trusty | * |
Phantomjs | Ubuntu | xenial | * |
Pyside | Ubuntu | bionic | * |
Pyside | Ubuntu | eoan | * |
Pyside | Ubuntu | esm-apps/bionic | * |
Pyside | Ubuntu | esm-apps/xenial | * |
Pyside | Ubuntu | esm-infra-legacy/trusty | * |
Pyside | Ubuntu | trusty | * |
Pyside | Ubuntu | trusty/esm | * |
Pyside | Ubuntu | xenial | * |
Pyside2 | Ubuntu | devel | * |
Pyside2 | Ubuntu | eoan | * |
Pyside2 | Ubuntu | esm-apps/focal | * |
Pyside2 | Ubuntu | esm-apps/jammy | * |
Pyside2 | Ubuntu | esm-apps/noble | * |
Pyside2 | Ubuntu | focal | * |
Pyside2 | Ubuntu | groovy | * |
Pyside2 | Ubuntu | hirsute | * |
Pyside2 | Ubuntu | impish | * |
Pyside2 | Ubuntu | jammy | * |
Pyside2 | Ubuntu | kinetic | * |
Pyside2 | Ubuntu | lunar | * |
Pyside2 | Ubuntu | mantic | * |
Pyside2 | Ubuntu | noble | * |
Pyside2 | Ubuntu | oracular | * |
Pyside2 | Ubuntu | trusty | * |
Qt4-x11 | Ubuntu | bionic | * |
Qt4-x11 | Ubuntu | eoan | * |
Qt4-x11 | Ubuntu | esm-apps/bionic | * |
Qt4-x11 | Ubuntu | esm-infra-legacy/trusty | * |
Qt4-x11 | Ubuntu | esm-infra/xenial | * |
Qt4-x11 | Ubuntu | trusty | * |
Qt4-x11 | Ubuntu | trusty/esm | * |
Qt4-x11 | Ubuntu | xenial | * |
Qtbase-opensource-src | Ubuntu | bionic | * |
Qtbase-opensource-src | Ubuntu | eoan | * |
Qtbase-opensource-src | Ubuntu | esm-infra/bionic | * |
Qtbase-opensource-src | Ubuntu | esm-infra/xenial | * |
Qtbase-opensource-src | Ubuntu | trusty | * |
Qtbase-opensource-src | Ubuntu | xenial | * |