CVE-2023-32573 Name CVE-2023-32573 Description In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled. Source CVE (at NVD ; CERT , LWN , oss-sec , fulldisc , Red Hat , Ubuntu , Gentoo , SUSE bugzilla /CVE , GitHub advisories /code /issues , web search , more )References DLA-3539-1
Vulnerable and fixed packages The table below lists information on source packages.
Source Package Release Version Status qt6-svg (PTS )bookworm 6.4.2-2 fixed sid, trixie 6.7.2-4 fixed qtsvg-opensource-src (PTS )bullseye 5.15.2-3 vulnerable bookworm 5.15.8-3 fixed sid, trixie 5.15.15-2 fixed
The information below is based on the following data on fixed versions.
Notes [bullseye] - qtsvg-opensource-src <no-dsa> (Minor issue) [buster] - qtsvg-opensource-src <no-dsa> (Minor issue) https://codereview.qt-project.org/c/qt/qtsvg/+/474093 https://lists.qt-project.org/pipermail/announce/2023-May/000411.html https://codereview.qt-project.org/c/qt/qtsvg/+/474404 https://download.qt.io/official_releases/qt/5.15/CVE-2023-32573-qtsvg-5.15.diff