CVE-2023-24607
Dashboard / Vulnerabilities / CVE-2023-24607
CVE-2023-24607
Summary:
Details: Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.
References: https://codereview.qt-project.org/c/qt/qtbase/+/456216, https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/456217, https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/456238, https://download.qt.io/official_releases/qt/5.15/CVE-2023-24607-qtbase-5.15.diff, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24607.json, https://nvd.nist.gov/vuln/detail/CVE-2023-24607, https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin, https://github.com/qt/qtbase/commit/aaf1381eab6292aa0444a5eadcc24165b6e1c02d, https://lists.debian.org/debian-lts-announce/2024/04/msg00027.html, https://www.qt.io/blog/tag/security
Affected packages
Package
Name:
Purl:
