File CVE-2025-5455.patch of Package libqt4.40303
--- qt-everywhere-opensource-src-4.8.7/src/corelib/io/qdataurl.cpp 2015-05-07 16:14:48.000000000 +0200
+++ qt-everywhere-opensource-src-4.8.7/src/corelib/io/qdataurl.cpp 2025-08-18 22:15:41.749242004 +0200
@@ -83,9 +83,9 @@
if (data.toLower().startsWith("charset")) {
int i = 7; // strlen("charset")
- while (data.at(i) == ' ')
+ while (i < data.size() && data.at(i) == ' ')
++i;
- if (data.at(i) == '=')
+ if (i < data.size() && data.at(i) == '=')
data.prepend("text/plain;");
}
Nur in b/qt-everywhere-opensource-src-4.8.7/src/corelib/io: qdataurl.cpp.orig.
Nur in b/qt-everywhere-opensource-src-4.8.7/src/corelib/io: qdataurl.cpp.rej.