CVE-2023-32573Divide By Zero in QT

CWE-369Divide By Zero8 documents8 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 79.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 10
Latest updateFeb 15

Description

In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDqt/qt6.0.06.2.9+2

Also affects: Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-pjf4-g4fp-5xqm: In Qt before 52023-05-10
OSV
CVE-2023-32573: In Qt before 52023-05-10
CVEList
CVE-2023-32573: In Qt before 52023-05-10

📋Vendor Advisories

4
CISA ICS
Siemens SCALANCE XCM-/XRM-3002024-02-15
Red Hat
qt: Uninitialized variable usage in m_unitsPerEm2023-05-10
Microsoft
In Qt before 5.15.14 6.0.x through 6.2.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1 QtSvg QSvgFont m_unitsPerEm initialization is mishandled.2023-05-09
Debian
CVE-2023-32573: qt6-svg - In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x ...2023
CVE-2023-32573 — Divide By Zero in QT | cvebase