Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-43591

Опубликовано: 12 янв. 2023
Источник: debian
EPSS Низкий

Описание

A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qt6-declarativefixed6.4.2+dfsg~rc1-2package
qtdeclarative-opensource-srcunfixedpackage
qtdeclarative-opensource-src-glesunfixedpackage

Примечания

  • Not considered a security issue, QML only supported from a trusted source

  • https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1650

  • https://www.qt.io/blog/regarding-recent-reported-security-vulnerabilities-from-cisco-talos

  • https://bugreports.qt.io/browse/QTBUG-107619

  • https://codereview.qt-project.org/c/qt/qtdeclarative/+/437789

EPSS

Процентиль: 80%
0.01396
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

CVSS3: 8.8
nvd
около 3 лет назад

A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

CVSS3: 8.8
github
около 3 лет назад

A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

EPSS

Процентиль: 80%
0.01396
Низкий