CVE Vulnerabilities

CVE-2023-32573

Divide By Zero

Published: May 10, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Qt Qt * 5.15.14 (excluding)
Qt Qt 6.0.0 (including) 6.2.9 (excluding)
Qt Qt 6.3.0 (including) 6.5.1 (excluding)
Red Hat Enterprise Linux 8 RedHat qt5-qtsvg-0:5.15.3-2.el8 *
Red Hat Enterprise Linux 9 RedHat qt5-0:5.15.9-1.el9 *
Qt6-svg Ubuntu kinetic *
Qt6-svg Ubuntu lunar *
Qt6-svg Ubuntu mantic *
Qt6-svg Ubuntu trusty *
Qt6-svg Ubuntu xenial *
Qtsvg-opensource-src Ubuntu bionic *
Qtsvg-opensource-src Ubuntu kinetic *
Qtsvg-opensource-src Ubuntu lunar *
Qtsvg-opensource-src Ubuntu mantic *
Qtsvg-opensource-src Ubuntu trusty *
Qtsvg-opensource-src Ubuntu xenial *

References