Qt 6.0.0 至 6.8.8 以及 6.9.0 至 6.11.1 版本中,Qt Group 的 Qt 中 QtNetwork 模块在解析 HTTP 响应中的 Cache-Control 响应头时存在越界读取(缓冲区长于实际内容/缓冲区过度读取)漏洞。该漏洞允许远程攻击者通过返回一个异常大的 Cache-Control 头值给使用 QNetworkAccessManager 的应用程序,导致拒绝服务(应用程序崩溃)。 该漏洞仅影响连接的客户端一侧,且 32 位构建不受影响;该越界访问为只读操作,不会导致信息泄露,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet