CVE Vulnerabilities

CVE-2023-24607

Published: Apr 15, 2023 | Modified: May 01, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.

Affected Software

Name Vendor Start Version End Version
Qt Qt 5.0.0 (including) 5.15.13 (excluding)
Qt Qt 6.0.0 (including) 6.2.8 (excluding)
Qt Qt 6.3.0 (including) 6.4.3 (excluding)
Qt6-base Ubuntu kinetic *
Qt6-base Ubuntu lunar *
Qt6-base Ubuntu mantic *
Qt6-base Ubuntu trusty *
Qt6-base Ubuntu xenial *
Qtbase-opensource-src Ubuntu bionic *
Qtbase-opensource-src Ubuntu devel *
Qtbase-opensource-src Ubuntu esm-apps/focal *
Qtbase-opensource-src Ubuntu esm-apps/jammy *
Qtbase-opensource-src Ubuntu esm-apps/noble *
Qtbase-opensource-src Ubuntu esm-infra/bionic *
Qtbase-opensource-src Ubuntu esm-infra/xenial *
Qtbase-opensource-src Ubuntu focal *
Qtbase-opensource-src Ubuntu jammy *
Qtbase-opensource-src Ubuntu kinetic *
Qtbase-opensource-src Ubuntu lunar *
Qtbase-opensource-src Ubuntu mantic *
Qtbase-opensource-src Ubuntu noble *
Qtbase-opensource-src Ubuntu trusty *
Qtbase-opensource-src Ubuntu upstream *
Qtbase-opensource-src Ubuntu xenial *
Qtbase-opensource-src-gles Ubuntu kinetic *
Qtbase-opensource-src-gles Ubuntu lunar *
Qtbase-opensource-src-gles Ubuntu mantic *
Qtbase-opensource-src-gles Ubuntu trusty *
Qtbase-opensource-src-gles Ubuntu xenial *

References