CVE-2023-34410: Debian Linux
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
Affected products
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 38 only
- Qt Qt: from 5.13.0, before 5.15.15 (fixed in 5.15.15); from 6.0.0, before 6.2.9 (fixed in 6.2.9); from 6.3.0, before 6.5.2 (fixed in 6.5.2)
Published 2023-06-05. Last modified 2026-06-17.