CVE Vulnerabilities

CVE-2020-24742

Published: Aug 09, 2021 | Modified: Jun 17, 2026
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

Affected Software

NameVendorStart VersionEnd Version
QtQt5.6.0 (including)5.12.7 (excluding)
QtQt5.13.0 (including)5.13.2 (including)
Qtbase-opensource-srcUbuntutrusty*
Qtbase-opensource-srcUbuntuxenial*
Qtbase-opensource-src-glesUbuntuxenial*

References