First published: Fri Feb 28 2020(Updated: )
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | <=5.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21035 is a vulnerability in the WebSocket implementation of Qt through 5.14.1.
CVE-2018-21035 has a severity level of 7.5 (high).
CVE-2018-21035 affects Qt through version 5.14.1.
CVE-2018-21035 allows attackers to cause a denial of service by consuming excessive memory.
Yes, a fix is available for CVE-2018-21035. It is recommended to update Qt to a version beyond 5.14.1.