Описание
When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| qt6-svg | fixed | 6.9.2-3 | package | |
| qt6-svg | no-dsa | trixie | package | |
| qt6-svg | not-affected | bookworm | package | |
| qtsvg-opensource-src | not-affected | package |
Примечания
https://bugreports.qt.io/browse/QTBUG-137553
Introduced by: https://codereview.qt-project.org/c/qt/qtsvg/+/616712
Introduced by: https://code.qt.io/cgit/qt/qtsvg.git/commit/?id=0332df304f013ded362537c1f61556098b875352
Fixed by: https://codereview.qt-project.org/c/qt/qtsvg/+/654200
Fixed by: https://code.qt.io/cgit/qt/qtsvg.git/commit/?id=9e5bed9584ab65d56cd5fbac0471e06e37a54412 (dev)
Fixed by: https://code.qt.io/cgit/qt/qtsvg.git/commit/?id=ea44b50c6e61104cadd6b7c8ede92a4108634232 (v6.9.3)
EPSS
Связанные уязвимости
When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
Уязвимость функции renderPattern() кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании
EPSS