﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
19320	Patch Qt5 against CVE-2024-25580	Douglas R. Reno	Douglas R. Reno	"In Qt6 (see #19316), there were two security vulnerabilities fixed. I decided to look at Qt5 to see if it was vulnerable to both of these vulnerabilities, and upstream has made fixes available at:

- https://download.qt.io/official_releases/qt/5.15/0001-CVE-2023-51714-qtbase-5.15.diff
- https://download.qt.io/official_releases/qt/5.15/0002-CVE-2023-51714-qtbase-5.15.diff
- https://download.qt.io/official_releases/qt/5.15/CVE-2024-25580-qtbase-5.15.diff

I'll try to get this and Qt6 in tomorrow/Saturday.

For more information on CVE-2024-25580, see https://www.qt.io/blog/security-advisory-potential-buffer-overflow-when-reading-ktx-images

https://nvd.nist.gov/vuln/detail/CVE-2023-51714 is marked as 9.8 CRITICAL"	enhancement	closed	high	12.1	BOOK	git	medium	fixed		
