9.8
CVSSv3

CVE-2023-51714

Published: 24/12/2023 Updated: 01/05/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in the HTTP2 implementation in Qt prior to 5.15.17, 6.x prior to 6.2.11, 6.3.x up to and including 6.5.x prior to 6.5.4, and 6.6.x prior to 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt

Vendor Advisories

Debian Bug report logs - #1060693 qt6-base: CVE-2023-51714 Package: src:qt6-base; Maintainer for src:qt6-base is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 12 Jan 2024 22:15:02 UTC Severity: important Tags: security, upstream Reply or ...
An issue was discovered in the HTTP2 implementation in Qt before 51517, 6x before 6211, 63x through 65x before 654, and 66x before 662 network/access/http2/hpacktablecpp has an incorrect HPack integer overflow check (CVE-2023-51714) ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...