- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202312-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: QtWebEngine: Multiple Vulnerabilities Date: December 22, 2023 Bugs: #913050, #915465 ID: 202312-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilitiies have been discovered in QtWebEngine, the worst of which could lead to remote code execution. Background ========= QtWebEngine is a library for rendering dynamic web content in Qt5 and Qt6 C++ and QML applications. Affected packages ================ Package Vulnerable Unaffected ------------------ ------------------- -------------------- dev-qt/qtwebengine < 5.15.11_p20231120 >= 5.15.11_p20231120 Description ========== Multiple vulnerabilities have been discovered in QtWebEngine. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All QtWebEngine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">Þv-qt/qtwebengine-5.15.11_p20231120" References ========= [ 1 ] CVE-2023-4068 https://nvd.nist.gov/vuln/detail/CVE-2023-4068 [ 2 ] CVE-2023-4069 https://nvd.nist.gov/vuln/detail/CVE-2023-4069 [ 3 ] CVE-2023-4070 https://nvd.nist.gov/vuln/detail/CVE-2023-4070 [ 4 ] CVE-2023-4071 https://nvd.nist.gov/vuln/detail/CVE-2023-4071 [ 5 ] CVE-2023-4072 https://nvd.nist.gov/vuln/detail/CVE-2023-4072 [ 6 ] CVE-2023-4073 https://nvd.nist.gov/vuln/detail/CVE-2023-4073 [ 7 ] CVE-2023-4074 https://nvd.nist.gov/vuln/detail/CVE-2023-4074 [ 8 ] CVE-2023-4075 https://nvd.nist.gov/vuln/detail/CVE-2023-4075 [ 9 ] CVE-2023-4076 https://nvd.nist.gov/vuln/detail/CVE-2023-4076 [ 10 ] CVE-2023-4077 https://nvd.nist.gov/vuln/detail/CVE-2023-4077 [ 11 ] CVE-2023-4078 https://nvd.nist.gov/vuln/detail/CVE-2023-4078 [ 12 ] CVE-2023-4761 https://nvd.nist.gov/vuln/detail/CVE-2023-4761 [ 13 ] CVE-2023-4762 https://nvd.nist.gov/vuln/detail/CVE-2023-4762 [ 14 ] CVE-2023-4763 https://nvd.nist.gov/vuln/detail/CVE-2023-4763 [ 15 ] CVE-2023-4764 https://nvd.nist.gov/vuln/detail/CVE-2023-4764 [ 16 ] CVE-2023-5218 https://nvd.nist.gov/vuln/detail/CVE-2023-5218 [ 17 ] CVE-2023-5473 https://nvd.nist.gov/vuln/detail/CVE-2023-5473 [ 18 ] CVE-2023-5474 https://nvd.nist.gov/vuln/detail/CVE-2023-5474 [ 19 ] CVE-2023-5475 https://nvd.nist.gov/vuln/detail/CVE-2023-5475 [ 20 ] CVE-2023-5476 https://nvd.nist.gov/vuln/detail/CVE-2023-5476 [ 21 ] CVE-2023-5477 https://nvd.nist.gov/vuln/detail/CVE-2023-5477 [ 22 ] CVE-2023-5478 https://nvd.nist.gov/vuln/detail/CVE-2023-5478 [ 23 ] CVE-2023-5479 https://nvd.nist.gov/vuln/detail/CVE-2023-5479 [ 24 ] CVE-2023-5480 https://nvd.nist.gov/vuln/detail/CVE-2023-5480 [ 25 ] CVE-2023-5481 https://nvd.nist.gov/vuln/detail/CVE-2023-5481 [ 26 ] CVE-2023-5482 https://nvd.nist.gov/vuln/detail/CVE-2023-5482 [ 27 ] CVE-2023-5483 https://nvd.nist.gov/vuln/detail/CVE-2023-5483 [ 28 ] CVE-2023-5484 https://nvd.nist.gov/vuln/detail/CVE-2023-5484 [ 29 ] CVE-2023-5485 https://nvd.nist.gov/vuln/detail/CVE-2023-5485 [ 30 ] CVE-2023-5486 https://nvd.nist.gov/vuln/detail/CVE-2023-5486 [ 31 ] CVE-2023-5487 https://nvd.nist.gov/vuln/detail/CVE-2023-5487 [ 32 ] CVE-2023-5849 https://nvd.nist.gov/vuln/detail/CVE-2023-5849 [ 33 ] CVE-2023-5850 https://nvd.nist.gov/vuln/detail/CVE-2023-5850 [ 34 ] CVE-2023-5851 https://nvd.nist.gov/vuln/detail/CVE-2023-5851 [ 35 ] CVE-2023-5852 https://nvd.nist.gov/vuln/detail/CVE-2023-5852 [ 36 ] CVE-2023-5853 https://nvd.nist.gov/vuln/detail/CVE-2023-5853 [ 37 ] CVE-2023-5854 https://nvd.nist.gov/vuln/detail/CVE-2023-5854 [ 38 ] CVE-2023-5855 https://nvd.nist.gov/vuln/detail/CVE-2023-5855 [ 39 ] CVE-2023-5856 https://nvd.nist.gov/vuln/detail/CVE-2023-5856 [ 40 ] CVE-2023-5857 https://nvd.nist.gov/vuln/detail/CVE-2023-5857 [ 41 ] CVE-2023-5858 https://nvd.nist.gov/vuln/detail/CVE-2023-5858 [ 42 ] CVE-2023-5859 https://nvd.nist.gov/vuln/detail/CVE-2023-5859 [ 43 ] CVE-2023-5996 https://nvd.nist.gov/vuln/detail/CVE-2023-5996 [ 44 ] CVE-2023-5997 https://nvd.nist.gov/vuln/detail/CVE-2023-5997 [ 45 ] CVE-2023-6112 https://nvd.nist.gov/vuln/detail/CVE-2023-6112 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202312-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5