Improper Handling of Length Parameter Inconsistency in Qt - CVE-2023-43114
Published: June 14, 2024
Vulnerability identifier: #VU92115
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43114
CWE-ID: CWE-130
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability occurs when a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData]. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Qt
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Pair
Dell Peripheral Manager
Cisco Jabber
openEuler
Cisco Webex Meetings
VMware Horizon Client
qt-debuginfo
qt-debugsource
qt-devel
qt
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Pair
Dell Peripheral Manager
Cisco Jabber
openEuler
Cisco Webex Meetings
VMware Horizon Client
qt-debuginfo
qt-debugsource
qt-devel
qt
How to mitigate CVE-2023-43114
Install updates from vendor's website.
Qt - addressed in versions 5.15.16, 6.2.10, 6.5.3
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Pair - update to 1.2.3
Dell Peripheral Manager - update to 1.7.3
qt-debuginfo - addressed in versions 4.8.7-55, 4.8.7-58
qt-debugsource - addressed in versions 4.8.7-55, 4.8.7-58
qt-devel - addressed in versions 4.8.7-55, 4.8.7-58
qt - addressed in versions 4.8.7-55, 4.8.7-58
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Pair - update to 1.2.3
Dell Peripheral Manager - update to 1.7.3
qt-debuginfo - addressed in versions 4.8.7-55, 4.8.7-58
qt-debugsource - addressed in versions 4.8.7-55, 4.8.7-58
qt-devel - addressed in versions 4.8.7-55, 4.8.7-58
qt - addressed in versions 4.8.7-55, 4.8.7-58
External References
Related Security Bulletins
- Multiple vulnerabilities in Dell Peripheral Manager
- openEuler 22.03 LTS SP1 update for qt
- openEuler 22.03 LTS SP2 update for qt
- openEuler 20.03 LTS SP1 update for qt
- openEuler 20.03 LTS SP3 update for qt
- openEuler 22.03 LTS update for qt
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in Dell Pair