Qt
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*
- >= 6.6.0, <= 6.8.3
- >= 6.9.0, <= 6.9.1
A denial-of-service vulnerability has been identified in Qt versions 6.6.0 through 6.8.3 and 6.9.0 through 6.9.1. The issue arises when values outside the expected range are passed to the QColorTransferGenericFunction, particularly through a crafted ICC profile using the QColorSpace::fromICCProfile method.
Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to become unresponsive or unavailable.
Users can upgrade to Qt versions 6.8.4 or 6.9.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.