CVE-2023-33285: Medium severity Qt QT vulnerability
Published May 22, 2023
·Updated
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
Affected Software
3 affected components
Qt QT>=5.0.0<5.15.4
Qt QT>=6.0.0<6.2.9
Qt QT>=6.3.0<6.5.1
Event History
May 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-33285.
2
What is the severity of CVE-2023-33285?
The severity of CVE-2023-33285 is medium, with a severity value of 5.3.
3
Which versions of Qt are affected by CVE-2023-33285?
This vulnerability affects Qt versions from 5.0.0 to 5.15.4, 6.0.0 to 6.2.9, and 6.3.0 to 6.5.1.
4
What is the issue with QDnsLookup in Qt?
QDnsLookup in Qt has a buffer over-read vulnerability, which can be exploited via a crafted reply from a DNS server.
5
Is there a fix available for CVE-2023-33285?
Yes, a fix is available. It is recommended to update to Qt versions 5.15.14, 6.2.9, or 6.5.1.