OSV-2023-797

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/kimageformats/OSV-2023-797.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-797
Published
2023-09-06T14:02:36.541753Z
Modified
2023-09-10T14:16:24.674920Z
Summary
Stack-buffer-overflow in QBuffer::readData
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=62075

Crash type: Stack-buffer-overflow WRITE {*}
Crash state:
QBuffer::readData
QIODevicePrivate::read
QDataStream::readRawData
References

Affected packages

OSS-Fuzz / kimageformats

Package

Name
kimageformats
Purl
pkg:generic/kimageformats

Affected ranges

Type
GIT
Repo
https://invent.kde.org/frameworks/kimageformats.git
Events
Introduced
bcec942cc92e0968c724a2c1f92b4cd048bf8fa7
Fixed
723f72930b66f5c188799de67ef8c953c0135880
Fixed
a981cefdd239ca44bfd12eb7d78dc0c0560f016d
Introduced
4badb3088e90d86208ed6bd435df7fe6a022be64
Fixed
0a6fbd88e90c0cc20d6911104734878161b113c3

Affected versions

v5.*

v5.110.0
v5.110.0-rc1

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

{
    "introduced_range": "66cb8c91d085dab74ecda971b983f1a4402143fd:b2b677b8a5e4c3cf34790eb990218217bf867c18",
    "fixed_range": "99bb24803a3cdc19d86e86e713ab5ec1d861ca75:a981cefdd239ca44bfd12eb7d78dc0c0560f016d"
}