CVE-2023-24607

NameCVE-2023-24607
DescriptionQt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3805-1, ELA-1083-1, ELA-1239-1
Debian Bugs1031871, 1031872

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qt6-base (PTS)bookworm6.4.2+dfsg-10fixed
sid, trixie6.7.2+dfsg-5fixed
qtbase-opensource-src (PTS)jessie, jessie (lts)5.3.2+dfsg-4+deb8u7fixed
stretch (security)5.7.1+dfsg-3+deb9u3vulnerable
stretch (lts), stretch5.7.1+dfsg-3+deb9u5fixed
buster, buster (lts)5.11.3+dfsg1-1+deb10u7fixed
buster (security)5.11.3+dfsg1-1+deb10u6vulnerable
bullseye5.15.2+dfsg-9+deb11u1fixed
bookworm5.15.8+dfsg-11+deb12u2fixed
sid, trixie5.15.15+dfsg-2fixed
qtbase-opensource-src-gles (PTS)bullseye5.15.2+dfsg-4fixed
bookworm5.15.8+dfsg-3fixed
sid, trixie5.15.15+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qt6-basesource(unstable)6.4.2+dfsg-71031871
qtbase-opensource-srcsourcejessie5.3.2+dfsg-4+deb8u7ELA-1239-1
qtbase-opensource-srcsourcestretch5.7.1+dfsg-3+deb9u5ELA-1239-1
qtbase-opensource-srcsourcebuster5.11.3+dfsg1-1+deb10u7ELA-1239-1
qtbase-opensource-srcsourcebullseye5.15.2+dfsg-9+deb11u1
qtbase-opensource-srcsource(unstable)5.15.8+dfsg-31031872
qtbase-opensource-src-glessource(unstable)(not affected)

Notes

- qtbase-opensource-src-gles <not-affected> (GLES build only ships libqt5gui5, not the DB modules, see #1031873)
https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin
https://github.com/qt/qtbase/commit/aaf1381eab6292aa0444a5eadcc24165b6e1c02d (6.4)
https://download.qt.io/official_releases/qt/5.15/CVE-2023-24607-qtbase-5.15.diff

Search for package or bug name: Reporting problems