Andy Shaw reports: QStringConverter has an invalid pointer being passed as a callback which can allow modification of the stack. Qt itself is not vulnerable to remote attack however an application using QStringDecoder either directly or indirectly can be vulnerable. This requires: Qt does not automatically use any of those codecs, so this needs the application to implement something using QStringDecoder to be vulnerable.