CVE-2024-39936

Public on 2024-07-04
Modified on 2024-10-25
Description
An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..
Severity
Important severity
Important
CVSS v3 Base Score
8.6
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core qt5 2024-10-24 ALAS2-2024-2675 Fixed
Amazon Linux 2 - Core qt5-qt3d 2024-10-24 ALAS2-2024-2659 Fixed
Amazon Linux 2 - Core qt5-qtbase 2024-10-24 ALAS2-2024-2678 Fixed
Amazon Linux 2 - Core qt5-qtcanvas3d 2024-10-24 ALAS2-2024-2664 Fixed
Amazon Linux 2 - Core qt5-qtconnectivity 2024-10-24 ALAS2-2024-2673 Fixed
Amazon Linux 2 - Core qt5-qtdeclarative 2024-10-24 ALAS2-2024-2676 Fixed
Amazon Linux 2 - Core qt5-qtgraphicaleffects 2024-10-24 ALAS2-2024-2672 Fixed
Amazon Linux 2 - Core qt5-qtimageformats 2024-10-24 ALAS2-2024-2671 Fixed
Amazon Linux 2 - Core qt5-qtlocation 2024-10-24 ALAS2-2024-2670 Fixed
Amazon Linux 2 - Core qt5-qtmultimedia 2024-10-24 ALAS2-2024-2669 Fixed
Amazon Linux 2 - Core qt5-qtquickcontrols 2024-10-24 ALAS2-2024-2668 Fixed
Amazon Linux 2 - Core qt5-qtscript 2024-10-24 ALAS2-2024-2667 Fixed
Amazon Linux 2 - Core qt5-qtsensors 2024-10-24 ALAS2-2024-2666 Fixed
Amazon Linux 2 - Core qt5-qtserialport 2024-10-24 ALAS2-2024-2665 Fixed
Amazon Linux 2 - Core qt5-qtsvg 2024-10-24 ALAS2-2024-2663 Fixed
Amazon Linux 2 - Core qt5-qttools 2024-10-24 ALAS2-2024-2677 Fixed
Amazon Linux 2 - Core qt5-qtwebchannel 2024-10-24 ALAS2-2024-2662 Fixed
Amazon Linux 2 - Core qt5-qtwebsockets 2024-10-24 ALAS2-2024-2661 Fixed
Amazon Linux 2 - Core qt5-qtx11extras 2024-10-24 ALAS2-2024-2660 Fixed
Amazon Linux 2 - Core qt5-qtxmlpatterns 2024-10-24 ALAS2-2024-2674 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
NVD CVSSv3 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N