Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-4025

Опубликовано: 06 окт. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-4025: qt5-qtbase security update (MODERATE)

[5.9.7-4]

  • Fix: Files placed by attacker can influence the working directory and lead to malicious code execution Resolves: bz#1814740 Resolves: bz#1814685

[5.9.7-3]

  • Fix multilib issue with qtcore-config.h header file Resolves: bz#1534528

  • Move libQt5EglFSDeviceIntegration lib into correct subpackage Resolves: bz#1792680

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

qt5-qtbase

5.9.7-4.el7

qt5-qtbase-common

5.9.7-4.el7

qt5-qtbase-devel

5.9.7-4.el7

qt5-qtbase-doc

5.9.7-4.el7

qt5-qtbase-examples

5.9.7-4.el7

qt5-qtbase-gui

5.9.7-4.el7

qt5-qtbase-mysql

5.9.7-4.el7

qt5-qtbase-odbc

5.9.7-4.el7

qt5-qtbase-postgresql

5.9.7-4.el7

qt5-qtbase-static

5.9.7-4.el7

qt5-rpm-macros

5.9.7-4.el7

Oracle Linux x86_64

qt5-qtbase

5.9.7-4.el7

qt5-qtbase-common

5.9.7-4.el7

qt5-qtbase-devel

5.9.7-4.el7

qt5-qtbase-doc

5.9.7-4.el7

qt5-qtbase-examples

5.9.7-4.el7

qt5-qtbase-gui

5.9.7-4.el7

qt5-qtbase-mysql

5.9.7-4.el7

qt5-qtbase-odbc

5.9.7-4.el7

qt5-qtbase-postgresql

5.9.7-4.el7

qt5-qtbase-static

5.9.7-4.el7

qt5-rpm-macros

5.9.7-4.el7

Связанные CVE

Связанные уязвимости

oracle-oval
больше 4 лет назад

ELSA-2020-4690: qt5-qtbase and qt5-qtwebsockets security and bug fix update (MODERATE)

CVSS3: 7.3
ubuntu
почти 5 лет назад

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

CVSS3: 7.3
redhat
больше 5 лет назад

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

CVSS3: 7.3
nvd
почти 5 лет назад

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

CVSS3: 7.3
msrc
почти 4 года назад

Описание отсутствует