CVE-2023-32763

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:04

Type Values Removed Values Added
References () https://codereview.qt-project.org/c/qt/qtbase/+/476125 - Patch () https://codereview.qt-project.org/c/qt/qtbase/+/476125 - Patch
References () https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html - () https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html -
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html -
References () https://lists.qt-project.org/pipermail/announce/2023-May/000413.html - Mailing List, Patch () https://lists.qt-project.org/pipermail/announce/2023-May/000413.html - Mailing List, Patch
References () https://security.gentoo.org/glsa/202402-03 - () https://security.gentoo.org/glsa/202402-03 -

01 May 2024, 01:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html -

03 Feb 2024, 07:15

Type Values Removed Values Added
References
  • () https://security.gentoo.org/glsa/202402-03 -

23 Aug 2023, 01:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html -

03 Jun 2023, 03:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Qt
Qt qt
CWE CWE-120
References (CONFIRM) https://lists.qt-project.org/pipermail/announce/2023-May/000413.html - (CONFIRM) https://lists.qt-project.org/pipermail/announce/2023-May/000413.html - Mailing List, Patch
References (MISC) https://codereview.qt-project.org/c/qt/qtbase/+/476125 - (MISC) https://codereview.qt-project.org/c/qt/qtbase/+/476125 - Patch
CPE cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*

28 May 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-28 23:15

Updated : 2024-11-21 08:04


NVD link : CVE-2023-32763

Mitre link : CVE-2023-32763

CVE.ORG link : CVE-2023-32763


JSON object : View

Products Affected

qt

  • qt
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')