CVE-2015-9541: High severity trolltech qt vulnerability
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2015-9541.
What is the severity level of CVE-2015-9541?
The severity level of CVE-2015-9541 is high with a score of 7.5.
Which software versions are affected by CVE-2015-9541?
Qt versions up to but excluding 5.15.0 and versions between 5.5.0 and 5.12.8, as well as Fedora versions 31 and 32, are affected by CVE-2015-9541.
How can I fix CVE-2015-9541?
To fix CVE-2015-9541, update Qt to version 5.15.0 or higher.
Where can I find more information about CVE-2015-9541?
You can find more information about CVE-2015-9541 on the following links: [Reference 1](https://bugreports.qt.io/browse/QTBUG-47417), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PT6327C64Q4RBFRWUSBKCG7SVGBWU5W/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZMMF4OEJAZRVKVXNO7IZWLEZVQGJN6G/).