Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:7482

Опубликовано: 08 нояб. 2022
Источник: rocky
Оценка: Moderate

Описание

Moderate: qt5 security, bug fix, and enhancement update

The Qt5 libraries packages provide Qt 5, version 5 of the Qt cross-platform application framework.

The following packages have been upgraded to a later upstream version: qt5 (5.15.3). (BZ#2061377)

Security Fix(es):

  • qt: QProcess could execute a binary from the current working directory when not found in the PATH (CVE-2022-25255)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
qt5-rpm-macrosnoarch1.el8qt5-rpm-macros-5.15.3-1.el8.noarch.rpm
qt5-srpm-macrosnoarch1.el8qt5-srpm-macros-5.15.3-1.el8.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS3: 7.8
redhat
больше 3 лет назад

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS3: 7.8
nvd
больше 3 лет назад

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS3: 7.8
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
больше 3 лет назад

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux ...