CVE-2024-25580
EUVD-2024-2290827.03.2024, 03:15
An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qt | qt | 5.12.0 ≤ 𝑥 < 5.15.17 |
| qt | qt | 6.0.0 ≤ 𝑥 < 6.2.12 |
| qt | qt | 6.3.0 ≤ 𝑥 < 6.5.5 |
| qt | qt | 6.6.0 ≤ 𝑥 < 6.6.2 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qt6-base |
| ||||||||||||||
| qtbase-opensource-src |
| ||||||||||||||
| qtbase-opensource-src-gles |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qt6-base |
| ||||||||||||||||||||
| qtbase-opensource-src |
| ||||||||||||||||||||
| qtbase-opensource-src-gles |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libQt6Core6 |
| ||||||||||||
| libQt6DBus6 |
| ||||||||||||
| libQt6Gui6 |
| ||||||||||||
| libQt6Network6 |
| ||||||||||||
| libQt6OpenGL6 |
| ||||||||||||
| libQt6Sql6 |
| ||||||||||||
| libQt6Test6 |
| ||||||||||||
| libQt6Widgets6 |
| ||||||||||||
| qt6-network-tls |
| ||||||||||||
| qt6-networkinformation-glib |
| ||||||||||||
| qt6-networkinformation-nm |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| qt5-qtbase |
| ||||
| qt5-qtbase-common |
| ||||
| qt5-qtbase-devel |
| ||||
| qt5-qtbase-examples |
| ||||
| qt5-qtbase-gui |
| ||||
| qt5-qtbase-mysql |
| ||||
| qt5-qtbase-odbc |
| ||||
| qt5-qtbase-postgresql |
| ||||
| qt5-qtbase-private-devel |
| ||||
| qt5-qtbase-static |
|
References