GLSA-202101-30 : Qt WebEngine: Multiple vulnerabilities

critical Nessus Plugin ID 145430

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-202101-30 (Qt WebEngine: Multiple vulnerabilities)

Multiple vulnerabilities have been discovered in Qt WebEngine. Please review the CVE identifiers referenced below for details.
Impact :

Please review the referenced CVE identifiers for details.
Workaround :

There is no known workaround at this time.

Solution

All Qt WebEngine users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=dev-qt/qtwebengine-5.15.2'

See Also

https://security.gentoo.org/glsa/202101-30

Plugin Details

Severity: Critical

ID: 145430

File Name: gentoo_GLSA-202101-30.nasl

Version: 1.3

Type: local

Published: 1/26/2021

Updated: 5/12/2022

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: E:POC/RL:OF/RC:C

CVSS Score Source: CVE-2020-6559

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:qtwebengine, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/26/2021

Vulnerability Publication Date: 5/21/2020

Reference Information

CVE: CVE-2020-15959, CVE-2020-15960, CVE-2020-15961, CVE-2020-15962, CVE-2020-15963, CVE-2020-15964, CVE-2020-15965, CVE-2020-15966, CVE-2020-15968, CVE-2020-15969, CVE-2020-15972, CVE-2020-15974, CVE-2020-15976, CVE-2020-15977, CVE-2020-15978, CVE-2020-15979, CVE-2020-15985, CVE-2020-15987, CVE-2020-15989, CVE-2020-15992, CVE-2020-16001, CVE-2020-16002, CVE-2020-16003, CVE-2020-6467, CVE-2020-6470, CVE-2020-6471, CVE-2020-6472, CVE-2020-6473, CVE-2020-6474, CVE-2020-6475, CVE-2020-6476, CVE-2020-6480, CVE-2020-6481, CVE-2020-6482, CVE-2020-6483, CVE-2020-6486, CVE-2020-6487, CVE-2020-6489, CVE-2020-6490, CVE-2020-6506, CVE-2020-6510, CVE-2020-6511, CVE-2020-6512, CVE-2020-6513, CVE-2020-6514, CVE-2020-6518, CVE-2020-6523, CVE-2020-6524, CVE-2020-6526, CVE-2020-6529, CVE-2020-6530, CVE-2020-6531, CVE-2020-6532, CVE-2020-6533, CVE-2020-6534, CVE-2020-6535, CVE-2020-6540, CVE-2020-6541, CVE-2020-6542, CVE-2020-6543, CVE-2020-6544, CVE-2020-6545, CVE-2020-6548, CVE-2020-6549, CVE-2020-6550, CVE-2020-6551, CVE-2020-6555, CVE-2020-6557, CVE-2020-6559, CVE-2020-6561, CVE-2020-6562, CVE-2020-6569, CVE-2020-6570, CVE-2020-6571, CVE-2020-6573, CVE-2020-6575, CVE-2020-6576

GLSA: 202101-30