CVE-2023-38197: Buffer Overflow
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.1.117.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.2.5 - Upgrade
Upgrade
Qtto a version that resolves this vulnerability.Fixed in 5.15.15 - Upgrade
Upgrade
Qtto a version that resolves this vulnerability.Fixed in 6.2.10 - Upgrade
Upgrade
Qtto a version that resolves this vulnerability.Fixed in 6.5.3
Event History
Frequently Asked Questions
What is CVE-2023-38197?
CVE-2023-38197 is a vulnerability discovered in Qt that allows for infinite loops in recursive entity expansion.
What is the severity of CVE-2023-38197?
CVE-2023-38197 has a severity rating of high.
Which versions of Qt are affected by CVE-2023-38197?
Qt versions before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 are affected by CVE-2023-38197.
How can I fix CVE-2023-38197?
To fix CVE-2023-38197, update Qt to version 5.15.15 or higher, 6.2.10 or higher, or 6.5.3 or higher.
Is there any additional information about CVE-2023-38197?
Yes, you can find additional information about CVE-2023-38197 at the following references: [link1](https://codereview.qt-project.org/c/qt/qtbase/+/488960), [link2](https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F5C3NYVJ73ITE6HUOVVHBUAGORVEJRHO/).