NA

CVE-2023-24607

Published: 15/04/2023 Updated: 01/05/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Qt prior to 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x prior to 5.15.13, 6.x prior to 6.2.8, and 6.3.x prior to 6.4.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt

Vendor Advisories

Debian Bug report logs - #1031871 qt6-base: CVE-2023-24607 Package: src:qt6-base; Maintainer for src:qt6-base is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 24 Feb 2023 16:03:06 UTC Severity: important Tags: security, upstream Fixed in versi ...
When using the Qt SQL ODBC driver plugin, then it is possible to trigger a DOS with a specifically crafted string RESERVEDNOTE: wwwqtio/blog/security-advisory-qt-sql-odbc-driver-pluginNOTE: githubcom/qt/qtbase/commit/aaf1381eab6292aa0444a5eadcc24165b6e1c02d (64)NOTE: downloadqtio/official_releases/qt/515/CVE-2023-2460 ...
DescriptionThe MITRE CVE dictionary describes this issue as: Qt before 643 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4 The affected versions are 5x before 51513, 6x before 628, and 63x before 643 ...