Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-24607

Опубликовано: 15 апр. 2023
Источник: debian
EPSS Низкий

Описание

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qtbase-opensource-srcfixed5.15.8+dfsg-3package
qtbase-opensource-srcfixed5.15.2+dfsg-9+deb11u1bullseyepackage
qt6-basefixed6.4.2+dfsg-7package
qtbase-opensource-src-glesnot-affectedpackage

Примечания

  • https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin

  • https://github.com/qt/qtbase/commit/aaf1381eab6292aa0444a5eadcc24165b6e1c02d (6.4)

  • https://download.qt.io/official_releases/qt/5.15/CVE-2023-24607-qtbase-5.15.diff

EPSS

Процентиль: 55%
0.00321
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.

CVSS3: 7.5
redhat
почти 3 года назад

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.

CVSS3: 7.5
nvd
почти 3 года назад

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.

CVSS3: 7.5
msrc
почти 3 года назад

Описание отсутствует

suse-cvrf
почти 3 года назад

Security update for qt6-base

EPSS

Процентиль: 55%
0.00321
Низкий