• Bug#1103022: qt6-base: CVE-2025-3512

    From Salvatore Bonaccorso@21:1/5 to All on Sun Apr 13 21:10:01 2025
    Source: qt6-base
    Version: 6.8.2+dfsg-5
    Severity: important
    Tags: security upstream
    X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

    Hi,

    The following vulnerability was published for qt6-base.

    CVE-2025-3512[0]:
    | There is a Heap-based Buffer Overflow vulnerability in
    | QTextMarkdownImporter. This requires an incorrectly formatted
    | markdown file to be passed to QTextMarkdownImporter to trigger the
    | overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to
    | 6.6.0 are known to be unaffected, and the fix is in 6.8.4 and later.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-3512
    https://www.cve.org/CVERecord?id=CVE-2025-3512
    [1] https://codereview.qt-project.org/c/qt/qtbase/+/635546

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)