First published: Fri Jan 24 2020(Updated: )
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Qt | <5.15.0 | 5.15.0 |
Qt Qt | >=5.5.0<5.12.8 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2015-9541.
The severity level of CVE-2015-9541 is high with a score of 7.5.
Qt versions up to but excluding 5.15.0 and versions between 5.5.0 and 5.12.8, as well as Fedora versions 31 and 32, are affected by CVE-2015-9541.
To fix CVE-2015-9541, update Qt to version 5.15.0 or higher.
You can find more information about CVE-2015-9541 on the following links: [Reference 1](https://bugreports.qt.io/browse/QTBUG-47417), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PT6327C64Q4RBFRWUSBKCG7SVGBWU5W/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZMMF4OEJAZRVKVXNO7IZWLEZVQGJN6G/).