An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Qt | Qt | 5.6.0 (including) | 5.12.7 (excluding) |
| Qt | Qt | 5.13.0 (including) | 5.13.2 (including) |
| Qtbase-opensource-src | Ubuntu | trusty | * |
| Qtbase-opensource-src | Ubuntu | xenial | * |
| Qtbase-opensource-src-gles | Ubuntu | trusty | * |
| Qtbase-opensource-src-gles | Ubuntu | xenial | * |