Wind River Support Network

HomeDefectsLIN1021-6552
Fixed

LIN1021-6552 : Security Advisory - qtbase - CVE-2023-43114

Created: Sep 18, 2023    Updated: Dec 3, 2023
Resolved Date: Dec 3, 2023
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks.

CREATE(Triage):(User=admin) CVE-2023-43114 (https://nvd.nist.gov/vuln/detail/CVE-2023-43114)

CVEs


Live chat
Online