Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24742

Опубликовано: 09 авг. 2021
Источник: debian

Описание

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qtbase-opensource-srcfixed5.12.5+dfsg-8package
qtbase-opensource-src-glesfixed5.14.2+dfsg-3package
qt4-x11not-affectedpackage

Примечания

  • https://codereview.qt-project.org/c/qt/qtbase/+/280730

  • Introduced in https://codereview.qt-project.org/gitweb?p=qt/qtbase.git;a=commitdiff;h=3146dadb42cb36aff83a62e831b8b4f4dc1562a7 (v5.6.0-alpha1)

  • Fixed by: https://codereview.qt-project.org/gitweb?p=qt/qtbase.git;a=commitdiff;h=bf131e8d2181b3404f5293546ed390999f760404 (v5.14.0-rc1)

  • Same fix as CVE-2020-0569

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

CVSS3: 7.8
redhat
больше 4 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

CVSS3: 7.8
nvd
больше 4 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

CVSS3: 7.8
msrc
около 4 лет назад

Описание отсутствует

github
больше 3 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.