4.8

CVE-2025-3512

Buffer overflow in QTextMarkdownImporter

There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.

This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix is in 6.8.4 and later.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerQt
≫
Produkt Qt
Default Statusunaffected
Version 0
Version < 6.6.0
Status unaffected
Version 6.6.0
Version < 6.8.0
Status unknown
Version 6.8.0
Version < 6.8.4
Status affected
Version 6.8.4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.132
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
a59d8014-47c4-4630-ab43-e1b13cbe58e3 4.8 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
CWE-122 Heap-based Buffer Overflow

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

https://codereview.qt-project.org/c/qt/qtbase/+/635546
http://www.openwall.com/lists/oss-security/2025/04/24/4
http://www.openwall.com/lists/oss-security/2025/04/24/5
http://www.openwall.com/lists/oss-security/2025/04/24/6
http://www.openwall.com/lists/oss-security/2025/04/25/1
http://www.openwall.com/lists/oss-security/2025/04/25/2