Upstream information

CVE-2024-36048 at MITRE

Description

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1224782 [NEW]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 15 SP5
  • libQt5NetworkAuth5 >= 5.15.2+kde2-bp155.3.3.1
  • libQt5NetworkAuth5-32bit >= 5.15.2+kde2-bp155.3.3.1
  • libQt5NetworkAuth5-64bit >= 5.15.2+kde2-bp155.3.3.1
  • libQt6NetworkAuth6 >= 6.4.2-bp155.2.3.1
  • libqt5-qtnetworkauth-devel >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-devel-32bit >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-devel-64bit >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-examples >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-private-headers-devel >= 5.15.2+kde2-bp155.3.3.1
  • qt6-networkauth-devel >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-docs-html >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-docs-qch >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-examples >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-private-devel >= 6.4.2-bp155.2.3.1
Patchnames:
openSUSE-2024-138
openSUSE-2024-143
openSUSE Leap 15.5
  • libQt5NetworkAuth5 >= 5.15.2+kde2-bp155.3.3.1
  • libQt5NetworkAuth5-32bit >= 5.15.2+kde2-bp155.3.3.1
  • libQt5NetworkAuth5-64bit >= 5.15.2+kde2-bp155.3.3.1
  • libQt6NetworkAuth6 >= 6.4.2-bp155.2.3.1
  • libqt5-qtnetworkauth-devel >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-devel-32bit >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-devel-64bit >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-examples >= 5.15.2+kde2-bp155.3.3.1
  • libqt5-qtnetworkauth-private-headers-devel >= 5.15.2+kde2-bp155.3.3.1
  • qt6-networkauth-devel >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-docs-html >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-docs-qch >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-examples >= 6.4.2-bp155.2.3.1
  • qt6-networkauth-private-devel >= 6.4.2-bp155.2.3.1
Patchnames:
openSUSE-2024-138
openSUSE-2024-143
openSUSE Tumbleweed
  • libQt5NetworkAuth5 >= 5.15.13+kde1-1.1
  • libQt6NetworkAuth6 >= 6.7.1-1.1
  • libqt5-qtnetworkauth-devel >= 5.15.13+kde1-1.1
  • libqt5-qtnetworkauth-examples >= 5.15.13+kde1-1.1
  • libqt5-qtnetworkauth-private-headers-devel >= 5.15.13+kde1-1.1
  • qt6-networkauth-devel >= 6.7.1-1.1
  • qt6-networkauth-examples >= 6.7.1-1.1
  • qt6-networkauth-private-devel >= 6.7.1-1.1
Patchnames:
openSUSE-Tumbleweed-2024-14003
openSUSE-Tumbleweed-2024-14006


SUSE Timeline for this CVE

CVE page created: Tue May 21 11:15:21 2024
CVE page last modified: Fri Jun 21 11:48:27 2024