-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 28 Apr 2024 22:48:02 +0200 Source: qtbase-opensource-src Binary: qtbase5-doc qtbase5-doc-dev qtbase5-doc-html Architecture: all Version: 5.15.2+dfsg-9+deb11u1 Distribution: bullseye Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Thorsten Alteholz Description: qtbase5-doc - Qt 5 base documentation qtbase5-doc-dev - Qt 5 base tags files qtbase5-doc-html - Qt 5 base HTML documentation Closes: 1031872 1036702 1036848 1037210 1041105 1059302 1060694 1064053 Changes: qtbase-opensource-src (5.15.2+dfsg-9+deb11u1) bullseye; urgency=medium . * Non-maintainer upload by the LTS Team. * CVE-2024-25580 (Closes: #1064053) fix buffer overflow due to crafted KTX image file * CVE-2023-32763 (Closes: #1036702) fix QTextLayout buffer overflow due to crafted SVG file * CVE-2022-25255 prevent QProcess from execution of a binary from the current working directory when not found in the PATH * CVE-2023-24607 (Closes: #1031872) fix denial of service via a crafted string when the SQL ODBC driver plugin is used * fix regression caused by patch for CVE-2023-24607 * CVE-2023-32762 prevent incorrect parsing of the strict-transport-security (HSTS) header * CVE-2023-51714 (Closes: #1060694) fix incorrect HPack integer overflow check. * CVE-2023-38197 (Closes: #1041105) fix infinite loop in recursive entity expansion * CVE-2023-37369 (Closes: #1059302) fix crash of application in QXmlStreamReader due to crafted XML string * CVE-2023-34410 (Closes: #1037210) fix checking during TLS whether root of the chain really is a configured CA certificate * CVE-2023-33285 (Closes: #1036848) fix buffer overflow in QDnsLookup Checksums-Sha1: 32a0ab918e2cf16467d173a1796589c6538fb0a8 18801 qtbase-opensource-src_5.15.2+dfsg-9+deb11u1_all-buildd.buildinfo 407e236c47689abedc37cfb940f7f566843b47bd 414212 qtbase5-doc-dev_5.15.2+dfsg-9+deb11u1_all.deb 8f38ac347264e9278497aa3e98f14a15e8bb97e4 20948032 qtbase5-doc-html_5.15.2+dfsg-9+deb11u1_all.deb 8239eab573bfbe16c34acc74e8063d379bbafca7 24224636 qtbase5-doc_5.15.2+dfsg-9+deb11u1_all.deb Checksums-Sha256: 57e60a720e2a03108562fb9b46c8c549f366cff2d9c9ea222605ff5709dd9a13 18801 qtbase-opensource-src_5.15.2+dfsg-9+deb11u1_all-buildd.buildinfo ca1ea738d022b13870dc165ad4a173a20b26b8605958aa3e6465e0127002127f 414212 qtbase5-doc-dev_5.15.2+dfsg-9+deb11u1_all.deb e297fff5d5fcb7136c71b8a3ebd5fcee81333cee1ffa3b87d44e700e38599450 20948032 qtbase5-doc-html_5.15.2+dfsg-9+deb11u1_all.deb cb1853c56bfa408c3484c8d82db13a6d3314dcafab8e25851ab38107d10230f8 24224636 qtbase5-doc_5.15.2+dfsg-9+deb11u1_all.deb Files: 80a1ecb45d549d16f745c736d5244d5a 18801 libs optional qtbase-opensource-src_5.15.2+dfsg-9+deb11u1_all-buildd.buildinfo b2b662972cb9cef670a0fa635731ebd2 414212 libdevel optional qtbase5-doc-dev_5.15.2+dfsg-9+deb11u1_all.deb 300acffe43e1a52df36eb32b30277de9 20948032 doc optional qtbase5-doc-html_5.15.2+dfsg-9+deb11u1_all.deb b6389ceb9a4adfb4d011d97bc1dfc7c7 24224636 doc optional qtbase5-doc_5.15.2+dfsg-9+deb11u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQsM0t1ygJv2xcx3e4cagXJhOTXsFAmZCcbwACgkQ4cagXJhO TXsAFRAArZbckI70nyX+0sjglb31hBg4XRbl4UGyqczbBUV9aP1H+nJdLpNXwGGe j4A+KSDVE32VdMJWUmbtDcVEhWXtXgJIg3WLU8X8soIvG9I2I5R/mxMQTqIxbAZF TjWthXcOfVgupt9Dyb5ac65H/n6110dzLbxYTVs2tQwANxTOB8w/L5sNPQRlZQn+ KjJjkn0kv1D0maMVFmWzoGknqfXfD1qPQo2X0b3TRMPw3UJ+FikE9KIl/zfiWp4n GKLsCN3OkNSyBKvHsJAz2cwTqo6ecJx9s5NgYjNe3TMdpHo0xFmF9+eRZzhCEnff /AhCI71yf2CfLSIR+bLCDe3Kbr/D4U26VTmUHlS2k3YLiv7UnHUGcwRzKFM46OMk 7nn4amWaJFEvRdvSCiCFCCV2vADu3jc9K9xwAsJKo2cG7aCPz9qLxOj14YI84Xw/ kFH7S8dOuEjvU27GXBoq66v7pRGyqhUK0DiYaN+w6oUZgvCKh3Y6RRzuIEoJTmN9 yDxqY//GSnZFm/+FrIfy+MOrT1lw2DSo6NsRVya9UPU2QVqtxKT06ZnVmzqWSgja PNro/qwPG9VxUkOYdVJj7QM7fy2PHUJC5/djXpb60N/qFXe0QJzqp8b5Oka079qq fde5zbfeRKaH2afH+Wetp0cSd/Xx4nwx83yOo0N0P4x49lkaefQ= =lrO8 -----END PGP SIGNATURE-----