CVE-2018-21035: High severity Qt QT vulnerability
In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
Other sources
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-21035?
CVE-2018-21035 is a vulnerability in the WebSocket implementation of Qt through 5.14.1.
What is the severity of CVE-2018-21035?
CVE-2018-21035 has a severity level of 7.5 (high).
How does CVE-2018-21035 affect Qt?
CVE-2018-21035 affects Qt through version 5.14.1.
What is the impact of CVE-2018-21035?
CVE-2018-21035 allows attackers to cause a denial of service by consuming excessive memory.
Is there a fix available for CVE-2018-21035?
Yes, a fix is available for CVE-2018-21035. It is recommended to update Qt to a version beyond 5.14.1.