CVE-2023-32763: Buffer Overflow
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
Other sources
CVE-2023-38197 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion. CVE-2023-37369 In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.
— F5
Qt is vulnerable to a denial of service, caused by a QTextLayout buffer overflow. By sending a specially crafted SVG file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-32763?
CVE-2023-32763 is a vulnerability found in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, which can trigger a QTextLayout buffer overflow when rendering an SVG file with an image inside it.
How severe is CVE-2023-32763?
CVE-2023-32763 has a severity value of 7, indicating a high severity.
How does CVE-2023-32763 affect Qt?
CVE-2023-32763 affects Qt versions before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1.
What is the CWE of CVE-2023-32763?
CVE-2023-32763 has the CWE (Common Weakness Enumeration) categories of 119 and 120.
Are there any references for CVE-2023-32763?
Yes, you can find more information about CVE-2023-32763 at the following references: [references](https://lists.qt-project.org/pipermail/announce/2023-May/000413.html), [references](https://codereview.qt-project.org/c/qt/qtbase/+/476125), [references](https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html).