Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-24742

Опубликовано: 09 авг. 2021
Источник: debian
EPSS Низкий

Описание

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qtbase-opensource-srcfixed5.12.5+dfsg-8package
qtbase-opensource-src-glesfixed5.14.2+dfsg-3package
qt4-x11not-affectedpackage

Примечания

  • https://codereview.qt-project.org/c/qt/qtbase/+/280730

  • Introduced in https://codereview.qt-project.org/gitweb?p=qt/qtbase.git;a=commitdiff;h=3146dadb42cb36aff83a62e831b8b4f4dc1562a7 (v5.6.0-alpha1)

  • Fixed by: https://codereview.qt-project.org/gitweb?p=qt/qtbase.git;a=commitdiff;h=bf131e8d2181b3404f5293546ed390999f760404 (v5.14.0-rc1)

  • Same fix as CVE-2020-0569

EPSS

Процентиль: 64%
0.01167
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

CVSS3: 7.8
redhat
почти 5 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

CVSS3: 7.8
nvd
почти 5 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

CVSS3: 7.8
msrc
больше 4 лет назад

Описание отсутствует

github
около 4 лет назад

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

EPSS

Процентиль: 64%
0.01167
Низкий