CVE-2023-37369: Buffer Overflow
CVE-2023-38197 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion. CVE-2023-37369 In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37369?
The severity of CVE-2023-37369 is high with a severity value of 7.5.
What is the affected software for CVE-2023-37369?
The affected software for CVE-2023-37369 includes Qt versions before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2.
How can CVE-2023-37369 be exploited?
CVE-2023-37369 can be exploited by crafting a malicious XML string that triggers a situation where a prefix is greater than a length.
Is there a fix available for CVE-2023-37369?
Yes, a fix is available for CVE-2023-37369. It is recommended to update to Qt version 5.15.15, 6.2.9, or 6.5.2.
Where can I find more information about CVE-2023-37369?
More information about CVE-2023-37369 can be found in the following references: [Link 1](https://bugreports.qt.io/browse/QTBUG-114829), [Link 2](https://codereview.qt-project.org/c/qt/qtbase/+/455027), [Link 3](https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html).