First published: Thu Jan 12 2023(Updated: )
An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | =6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40983 is an integer overflow vulnerability in the QML QtScript Reflect API of Qt Project Qt 6.3.2.
CVE-2022-40983 can be triggered by a specially-crafted javascript code that causes an integer overflow during memory allocation, potentially leading to arbitrary code execution.
CVE-2022-40983 has a severity rating of 8.8 (high).
Qt Project Qt 6.3.2 is affected by CVE-2022-40983.
To mitigate CVE-2022-40983, update Qt Project to a version that has a fix for the vulnerability.