CVE Vulnerabilities

CVE-2023-43114

Published: Sep 18, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks.

Affected Software

NameVendorStart VersionEnd Version
QtQt*5.15.16 (excluding)
QtQt6.0.0 (including)6.2.10 (excluding)
QtQt6.5.0 (including)6.5.3 (excluding)
Qt4-x11Ubuntubionic*
Qt4-x11Ubuntutrusty*
Qt4-x11Ubuntutrusty/esm*
Qt4-x11Ubuntuxenial*
Qt6-baseUbuntubionic*
Qt6-baseUbuntulunar*
Qt6-baseUbuntumantic*
Qt6-baseUbuntuoracular*
Qt6-baseUbuntuplucky*
Qt6-baseUbuntutrusty*
Qt6-baseUbuntuxenial*
Qtbase-opensource-srcUbuntubionic*
Qtbase-opensource-srcUbuntudevel*
Qtbase-opensource-srcUbuntuesm-apps/focal*
Qtbase-opensource-srcUbuntuesm-apps/jammy*
Qtbase-opensource-srcUbuntuesm-apps/noble*
Qtbase-opensource-srcUbuntuesm-infra/bionic*
Qtbase-opensource-srcUbuntuesm-infra/xenial*
Qtbase-opensource-srcUbuntufocal*
Qtbase-opensource-srcUbuntujammy*
Qtbase-opensource-srcUbuntulunar*
Qtbase-opensource-srcUbuntumantic*
Qtbase-opensource-srcUbuntunoble*
Qtbase-opensource-srcUbuntuoracular*
Qtbase-opensource-srcUbuntuplucky*
Qtbase-opensource-srcUbuntuquesting*
Qtbase-opensource-srcUbuntutrusty*
Qtbase-opensource-srcUbuntuxenial*
Qtbase-opensource-src-glesUbuntubionic*
Qtbase-opensource-src-glesUbuntudevel*
Qtbase-opensource-src-glesUbuntuesm-apps/focal*
Qtbase-opensource-src-glesUbuntuesm-apps/jammy*
Qtbase-opensource-src-glesUbuntuesm-apps/noble*
Qtbase-opensource-src-glesUbuntuesm-apps/xenial*
Qtbase-opensource-src-glesUbuntufocal*
Qtbase-opensource-src-glesUbuntujammy*
Qtbase-opensource-src-glesUbuntulunar*
Qtbase-opensource-src-glesUbuntumantic*
Qtbase-opensource-src-glesUbuntunoble*
Qtbase-opensource-src-glesUbuntuoracular*
Qtbase-opensource-src-glesUbuntuplucky*
Qtbase-opensource-src-glesUbuntuquesting*
Qtbase-opensource-src-glesUbuntutrusty*
Qtbase-opensource-src-glesUbuntuxenial*

References