Third-party software components

From SEGGER Knowledge Base
Jump to navigation Jump to search

SEGGER software products may include or make use of third-party software components. The presence of a third-party component does not necessarily mean that all functionality of that component is used by the SEGGER software. Likewise, a publicly disclosed vulnerability affecting a third-party component does not necessarily affect the SEGGER product in which the component is used. SEGGER evaluates relevant publicly disclosed vulnerabilities of third-party components with respect to their actual use in SEGGER software.

J-Link / Flasher Software and Documentation Pack

Qt

Some SEGGER host applications use the Qt4.8.7 framework for their graphical user interface and other application functionality, see SEGGER Qt usage.

CVE-2025-30348

CVE ID CVE-2025-30348
Affected component Qt XML module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2025/03/21
Publication date 2026/09/02
References
Impact assessment Availability impact only. Processing specially crafted large XML text during QDom serialization may cause excessive CPU usage, resulting in denial of service.
Severity and exploitability None. J-Link and Flasher software does not use nor ship Qt's XML module.

CVE-2025-4211

CVE ID CVE-2025-4211
Affected component Qt core module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2025/05/16
Publication date 2026/09/02
References
Impact assessment An unprivileged local attacker could potentially exploit insecure temporary-directory handling by privileged processes to influence file operations, potentially resulting in local privilege escalation.
Severity and exploitability Moderate. Exploitation requires local access and a privileged process using the affected Qt APIs, which limits the attack surface. However, successful exploitation could allow privilege escalation.

CVE-2023-43114

CVE ID CVE-2023-43114
Affected component Qt GUI module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2023/07/13
Publication date 2026/09/02
References
Impact assessment Malformed font data may trigger an out-of-bounds read in the Windows font parser, causing application crash (denial of service). Potential information disclosure cannot be ruled out but has not been demonstrated.
Severity and exploitability Low. Requires attacker-controlled font input. J-Link and Flasher applications do not explicitly load any user fonts. Primarily affects availability; no demonstrated arbitrary code execution.

CVE-2023-38197

CVE ID CVE-2023-38197
Affected component Qt Core module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2023/07/12
Publication date 2026/09/02
References
Impact assessment None:
  • Not applicable in the intended use of our software, as our software does not invoke QXmlStreamReader.
  • Even when attempting to force the vulnerability to occur with our builds using the reproducer that is provided in the respective Qt bug report, the described behavior cannot be observed.
Severity and exploitability None. The vulnerable code may exist in the shipped library, but it...
  1. ... is not reachable in the intended application
  2. ... is not even used by the Qt libraries, internally
  3. ... does not show a vulnerability when using the reported reproducer project

CVE-2023-37369

CVE ID CVE-2023-37369
Affected component Qt Core module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2023/07/07
Publication date 2026/09/02
References
Impact assessment Practically none:
  • Vulnerable library code (the whole affected class) is not used by our applications.
  • Qt libraries do not use the class internally, either.
  • SVG support, which uses vulnerable class, has been fully disabled and removed from the libraries.

Therefore, the vulnerable code path is not reachable in our applications.

Severity and exploitability Low:
  • Specially crafted XML file is required to run into vulnerability
  • Vulnerable code path is not reachable in our application

CVE-2023-32763

CVE ID CVE-2023-32763
Affected component Qt Gui module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2023/05/28
Publication date 2026/09/02
References
Impact assessment None:
  • Not applicable in the intended use of our software.
  • Even when attempting to force the vulnerability to occur with our builds using the reproducer that is provided in the respective Qt bug report, the described behavior cannot be observed.
Severity and exploitability Practically none. The vulnerable code may exist in the shipped library, but it does not show a vulnerability when using the reported reproducer project.

CVE-2020-17507

CVE ID CVE-2020-17507
Affected component Qt Gui module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2020/12/08
Publication date 2026/09/02
References
Impact assessment Malformed .xbm file may trigger an out-of-bounds read in the file payload data parser. Potential information disclosure cannot be ruled out but has not been demonstrated.
Severity and exploitability Low. Requires attacker-controlled .xbm data input. J-Link and Flasher applications do not explicitly load any user images or any .xbm files, at all. Primarily affects availability; no demonstrated arbitrary code execution.

CVE-2018-19873

CVE ID CVE-2018-19873
Affected component Qt Gui module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2018/12/26
Publication date None
References
Impact assessment A malformed .bmp file may lead to unnecessary allocation of memory as well as attempt to decode corrupt image file. Potential information disclosure cannot be ruled out but has not been demonstrated.
Severity and exploitability Low. Requires attacker-controlled .bmp data input. J-Link and Flasher applications do not explicitly load any user images or any .bmp files, at all. Primarily affects availability; no demonstrated arbitrary code execution.

CVE-2018-19870

CVE ID CVE-2018-19870
Affected component Qt GIF module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed
Fixed version V9.73 (RC) / V9.74
Discovery date 2018/12/26
Publication date 2026/09/02
References
Impact assessment Availability impact only. Processing specially crafted large .gif file may NULL pointer dereference, resulting in segmentation fault / denial of service.
Severity and exploitability None. J-Link and Flasher software does not use nor ship Qt's GIF module.

CVE-2014-0190

CVE ID CVE-2014-0190
Affected component Qt GIF module
Product version(s) Qt 4.8, used in V6.30[1] and later
Status Fixed already in Qt 4.8.7.
Fixed version V6.30[1] and later
Discovery date 2014/05/08
Publication date 2026/09/02
References
Impact assessment Availability impact only. Processing specially crafted large .gif file may NULL pointer dereference, resulting in segmentation fault / denial of service.
Severity and exploitability None. Vulnerability was patched from the beginning.
  1. ↑ 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 A GUI for macOS and Linux has been introduced in V6.30.

embOS

embOS does not use any third-party software. The entire source code is written by SEGGER Microcontroller.

Board support packages

embOS board support packages might include third-party software like, e.g. CMSIS-Core and CMSIS-Device files.