CVE Vulnerabilities

CVE-2020-24742

Published: Aug 09, 2021 | Modified: Aug 19, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

Affected Software

Name Vendor Start Version End Version
Qt Qt 5.6.0 (including) 5.12.7 (excluding)
Qt Qt 5.13.0 (including) 5.13.2 (including)
Qtbase-opensource-src Ubuntu trusty *
Qtbase-opensource-src Ubuntu xenial *
Qtbase-opensource-src-gles Ubuntu trusty *
Qtbase-opensource-src-gles Ubuntu xenial *

References