DEBIAN-CVE-2023-32762

Source
https://security-tracker.debian.org/tracker/CVE-2023-32762
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2023-32762.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2023-32762
Upstream
Published
2023-05-28T23:15:09.570Z
Modified
2025-11-17T04:25:58.173904Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

References

Affected packages

Debian:11

qtbase-opensource-src

Package

Name
qtbase-opensource-src
Purl
pkg:deb/debian/qtbase-opensource-src?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.2+dfsg-9+deb11u1

Affected versions

5.*

5.15.2+dfsg-9

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12

qt6-base

Package

Name
qt6-base
Purl
pkg:deb/debian/qt6-base?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2+dfsg-9

Ecosystem specific

{
    "urgency": "not yet assigned"
}

qtbase-opensource-src

Package

Name
qtbase-opensource-src
Purl
pkg:deb/debian/qtbase-opensource-src?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.8+dfsg-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13

qt6-base

Package

Name
qt6-base
Purl
pkg:deb/debian/qt6-base?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2+dfsg-9

Ecosystem specific

{
    "urgency": "not yet assigned"
}

qtbase-opensource-src

Package

Name
qtbase-opensource-src
Purl
pkg:deb/debian/qtbase-opensource-src?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.8+dfsg-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14

qt6-base

Package

Name
qt6-base
Purl
pkg:deb/debian/qt6-base?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2+dfsg-9

Ecosystem specific

{
    "urgency": "not yet assigned"
}

qtbase-opensource-src

Package

Name
qtbase-opensource-src
Purl
pkg:deb/debian/qtbase-opensource-src?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.8+dfsg-10

Ecosystem specific

{
    "urgency": "not yet assigned"
}