Wind River Support Network

HomeDefectsLIN1023-2141
Fixed

LIN1023-2141 : Security Advisory - qtbase - CVE-2023-43114

Created: Sep 19, 2023    Updated: Apr 20, 2024
Resolved Date: Mar 21, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.8
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks.

CREATE(Triage):(User=admin) CVE-2023-43114 (https://nvd.nist.gov/vuln/detail/CVE-2023-43114)

CVEs


Live chat
Online