Fix CVE-2023-24607
authorDebian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Sun, 28 May 2023 08:41:24 +0000 (09:41 +0100)
committerPatrick Franz <deltaone@debian.org>
Sun, 28 May 2023 08:41:24 +0000 (09:41 +0100)
commit949e4b8ac44f1e2b8f0d977738a39d4e59876195
tree24c22cdb511d8cb0a2566ed6bd32aec04f4c527d
parent1a372f505e31ec0626450f342cb99bec10154f2e
Fix CVE-2023-24607

Forwarded: not-needed

CVE-2023-24607 can trigger a DOS with a specifically crafted string,
see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1031871.
This patch https://codereview.qt-project.org/c/qt/qtbase/+/456216,
https://codereview.qt-project.org/c/qt/qtbase/+/457637 and
https://codereview.qt-project.org/c/qt/qtbase/+/457937
See: https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin

Gbp-Pq: Name cve-2023-24607.patch
src/plugins/sqldrivers/odbc/qsql_odbc.cpp