First published: Mon Sep 18 2023(Updated: )
An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trolltech Qt | <5.15.16 | |
Trolltech Qt | >=6.0.0<6.2.10 | |
Trolltech Qt | >=6.5.0<6.5.3 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-43114.
The severity of CVE-2023-43114 is medium (5.5).
The affected software for CVE-2023-43114 is Qt versions before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows.
CVE-2023-43114 can cause the application to crash when a corrupted font is loaded via QFontDatabase::addApplicationFontFromData on Windows.
No, Microsoft Windows is not vulnerable to CVE-2023-43114.