Описание
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
qt6-base | fixed | 6.6.2+dfsg-1 | experimental | package |
qt6-base | fixed | 6.6.2+dfsg-8 | package | |
qt6-base | no-dsa | bookworm | package | |
qtbase-opensource-src | fixed | 5.15.10+dfsg-7 | package | |
qtbase-opensource-src | fixed | 5.15.8+dfsg-11+deb12u2 | bookworm | package |
qtbase-opensource-src | fixed | 5.15.2+dfsg-9+deb11u1 | bullseye | package |
qtbase-opensource-src | not-affected | buster | package | |
qtbase-opensource-src-gles | fixed | 5.15.10+dfsg-5 | package | |
qtbase-opensource-src-gles | no-dsa | bookworm | package | |
qtbase-opensource-src-gles | no-dsa | bullseye | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2264423
https://code.qt.io/cgit/qt/qtbase.git/commit/?id=28ecb523ce8490bff38b251b3df703c72e057519
https://code.qt.io/cgit/qt/qtbase.git/commit/?id=dec1863c7dc63e5788b0c6c061d36e856a6ae2b2 (v6.6.2)
https://download.qt.io/official_releases/qt/5.15/CVE-2024-25580-qtbase-5.15.diff
https://www.qt.io/blog/security-advisory-potential-buffer-overflow-when-reading-ktx-images
EPSS
Связанные уязвимости
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
EPSS