CVE-2023-32763

Name
CVE-2023-32763
Description
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://lists.qt-project.org/pipermail/announce/2023-May/000413.html
MISC https://codereview.qt-project.org/c/qt/qtbase/+/476125
MLIST https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html
cve@mitre.org https://security.gentoo.org/glsa/202402-03
cve@mitre.org https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* qt >= 6.3.0 < 6.5.1
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* qt >= 6.0.0 < 6.2.9
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* qt >= None < 5.15.15

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
qt5-qtbase 3.18-community 5.15.9_git20230505-r0 Bart Ribbers <bribbers@disroot.org> fixed