PT-2024-13315 · Qt Company+2 · Qt+2

Gregory Duck

·

Published

2024-01-26

·

Updated

2024-12-20

·

CVE-2023-45935

CVSS v3.1

4.2

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Qt versions 6 through 6.6
Description A NULL pointer dereference was discovered via the function QXcbConnection::initializeAllAtoms(). This issue is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X server.
Recommendations For Qt versions 6 through 6.6, consider disabling the QXcbConnection::initializeAllAtoms() function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2023-45935
ECHO-2BCD-2D8F-ED84
OESA-2024-1537
OESA-2024-1538
OESA-2024-1539
OESA-2024-1540
OESA-2024-1614
OESA-2024-2572
SUSE-SU-2024:2873-1
SUSE-SU-2024:2882-1
SUSE-SU-2024:2883-1
SUSE-SU-2024:2890-1
SUSE-SU-2024:2946-1
SUSE-SU-2024_2873-1
SUSE-SU-2024_2882-1
SUSE-SU-2024_2883-1
SUSE-SU-2024_2890-1

Affected Products

Debian
Qt
Suse