[Development] WebSocket Module [CVE-2018-21035]

enstone83 at gmail.com enstone83 at gmail.com
Mon Mar 9 12:09:42 CET 2020


Hi,

I provided a patch for CVE-2018-21035, present in Qt5 WebSocket Module.
However apparently since the patch adds a new API it cannot go into Qt5.

This vulnerability makes the Qt5 WebSocket module totally unusable for 
use in non-trusted environment (like Internet).

Is there anything to do about it ?

https://nvd.nist.gov/vuln/detail/CVE-2018-21035
https://bugreports.qt.io/browse/QTBUG-70693
https://codereview.qt-project.org/c/qt/qtwebsockets/+/284735




More information about the Development mailing list