Fix CVE-2023-24607
authorDebian Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>
Sun, 17 Sep 2023 00:21:35 +0000 (01:21 +0100)
committerRaspbian forward porter <root@raspbian.org>
Sun, 17 Sep 2023 00:21:35 +0000 (01:21 +0100)
commitd04c4ef0e3674e6eb120f15d990196203a7e67a7
tree09689e3a27df72e32f4117d5abb1b17d59c16b51
parente3bd8b6eb9a70e977d14ed30a92a48744cc6a33a
Fix CVE-2023-24607

Forwarded: not-needed

CVE-2023-24607 can trigger a DOS with a specifically crafted string,
see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1031871.
This patch https://codereview.qt-project.org/c/qt/qtbase/+/456216,
https://codereview.qt-project.org/c/qt/qtbase/+/457637 and
https://codereview.qt-project.org/c/qt/qtbase/+/457937
See: https://www.qt.io/blog/security-advisory-qt-sql-odbc-driver-plugin

Gbp-Pq: Name cve-2023-24607.patch
src/plugins/sqldrivers/odbc/qsql_odbc.cpp