horsicq / DIE-engine

DIE engine
MIT License
2.29k stars 317 forks source link

CVE-2023-51714 Vulnerability #98

Open claudiudc opened 6 months ago

claudiudc commented 6 months ago

Hello,

I would like to raise a concern related to CVE-2023-51714 vulnerability. In our enterprise environment security scanners detected that latest release is impacted by CVE-2023-51714 vulnerability https://nvd.nist.gov/vuln/detail/CVE-2023-51714 Could you please help updating to a newer qt library to address this issue?

Also one more idea, will it be possible for the feature maybe to have a console version that is not using qt at all? From experience we see very frequently qt affected by different security vulnerabilities and in enterprise environments addressing security vulnerabilities is a critical process.

Kind Regards, Claudiu

horsicq commented 6 months ago

Hello! Thanks a lot for the bugreport! It will be fixed!.

modz2014 commented 6 months ago

it does not happen in Qt6

claudiudc commented 6 months ago

it does not happen in Qt6

It is "6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2"

modz2014 commented 6 months ago

ok i must have read it wrong