In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shotcut | Meltytech | * | 20.09.13 (excluding) |
Shotcut | Ubuntu | groovy | * |
Shotcut | Ubuntu | hirsute | * |
Shotcut | Ubuntu | impish | * |
Shotcut | Ubuntu | kinetic | * |
Shotcut | Ubuntu | lunar | * |
Shotcut | Ubuntu | mantic | * |
Shotcut | Ubuntu | trusty | * |