First published: Sun Dec 24 2023(Updated: )
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qt | <5.15.17 | 5.15.17 |
redhat/qt | <6.2.11 | 6.2.11 |
redhat/qt | <6.5.4 | 6.5.4 |
redhat/qt | <6.6.2 | 6.6.2 |
Trolltech Qt | <5.15.17 | |
Trolltech Qt | >=6.0.0<6.2.11 | |
Trolltech Qt | >=6.3.0<6.5.4 | |
Trolltech Qt | >=6.6.0<6.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51714 has been classified with a severity that may impact systems using affected QT versions due to an integer overflow in the HTTP2 implementation.
To fix CVE-2023-51714, upgrade the QT package to versions 5.15.17, 6.2.11, 6.5.4, or 6.6.2 or later.
QT versions prior to 5.15.17, between 6.0.0 and 6.2.11, between 6.3.0 and 6.5.4, and between 6.6.0 and 6.6.2 are affected by CVE-2023-51714.
CVE-2023-51714 is an integer overflow vulnerability found in the HTTP2 implementation of QT.
No, CVE-2023-51714 is not present in QT version 6.5.4 as it is a remedied version.