CVE-2023-33285
Summary
| CVE | CVE-2023-33285 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-22 03:15:00 UTC |
| Updated | 2023-06-07 17:42:00 UTC |
| Description | An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| codereview.qt-project.org/c/qt/qtbase/+/477644 | MISC | codereview.qt-project.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161064 Oracle Enterprise Linux Security Update for qt5 (ELSA-2023-6369)
- 161142 Oracle Enterprise Linux Security Update for qt5-qtbase (ELSA-2023-6967)
- 182046 Debian Security Update for qtbase-opensource-srcqt6-base (CVE-2023-33285)
- 242300 Red Hat Update for qt5 (RHSA-2023:6369)
- 242424 Red Hat Update for qt5-qtbase (RHSA-2023:6967)
- 754216 SUSE Enterprise Linux Security Update for libqt5-qtbase (SUSE-SU-2023:2971-1)
- 754253 SUSE Enterprise Linux Security Update for libqt5-qtbase (SUSE-SU-2023:3207-1)
- 907208 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (26943-1)
- 941352 AlmaLinux Security Update for qt5 (ALSA-2023:6369)
- 941424 AlmaLinux Security Update for qt5-qtbase (ALSA-2023:6967)