First published: Mon May 22 2023(Updated: )
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | >=5.0.0<5.15.4 | |
Qt Qt | >=6.0.0<6.2.9 | |
Qt Qt | >=6.3.0<6.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-33285.
The severity of CVE-2023-33285 is medium, with a severity value of 5.3.
This vulnerability affects Qt versions from 5.0.0 to 5.15.4, 6.0.0 to 6.2.9, and 6.3.0 to 6.5.1.
QDnsLookup in Qt has a buffer over-read vulnerability, which can be exploited via a crafted reply from a DNS server.
Yes, a fix is available. It is recommended to update to Qt versions 5.15.14, 6.2.9, or 6.5.1.