CVE-2023-32763Classic Buffer Overflow in QT

Severity
7.5HIGHNVD
EPSS
0.1%
top 73.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 28
Latest updateMay 29

Description

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

NVDqt/qt6.0.06.2.9+2
debiandebian/qt6-base< qt6-base 6.4.2+dfsg-8 (bookworm)
debiandebian/qtbase-opensource-src< qt6-base 6.4.2+dfsg-8 (bookworm)
debiandebian/qtbase-opensource-src-gles< qt6-base 6.4.2+dfsg-8 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j2m5-w7qp-hqg7: An issue was discovered in Qt before 52023-05-29
OSV
CVE-2023-32763: An issue was discovered in Qt before 52023-05-28

📋Vendor Advisories

2
Microsoft
An issue was discovered in Qt before 5.15.15 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered a QTextLayout buffer overflow can be triggered.2023-05-09
Debian
CVE-2023-32763: qt6-base - An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x throug...2023
CVE-2023-32763 — Classic Buffer Overflow in QT | cvebase