Alpine: multiple qt6-qtwebengine packages: security update to 6.6.3-r1

high Tenable Cloud Security Plugin ID 427088

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects
the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest
Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix
this issue. The associated identifier of this vulnerability is VDB-248999. (CVE-2023-7104)

- An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader
interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to
an xmlValidatePopElement use-after-free. (CVE-2024-25062)

See Also

https://security.alpinelinux.org/vuln/CVE-2023-7104

https://security.alpinelinux.org/vuln/CVE-2024-25062

Plugin Details

Severity: High

ID: 427088

Version: Revision 1.6

Type: Local

Published: 5/16/2025

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.49

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2023-7104

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 6/13/2023

Reference Information

CVE: CVE-2023-7104, CVE-2024-25062