CVE Vulnerabilities

CVE-2022-25255

Published: Feb 16, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

Affected Software

NameVendorStart VersionEnd Version
QtQt5.9.0 (including)5.15.9 (excluding)
QtQt6.0.0 (including)6.2.4 (excluding)
Red Hat Enterprise Linux 8RedHatqt5-0:5.15.3-1.el8*
Red Hat Enterprise Linux 9RedHatqt5-0:5.15.3-1.el9*
Qt6-baseUbuntukinetic*
Qt6-baseUbuntulunar*
Qt6-baseUbuntumantic*
Qt6-baseUbuntuoracular*
Qt6-baseUbuntuplucky*
Qt6-baseUbuntutrusty*
Qt6-baseUbuntuxenial*
Qtbase-opensource-srcUbuntuesm-apps/focal*
Qtbase-opensource-srcUbuntufocal*
Qtbase-opensource-srcUbuntuimpish*
Qtbase-opensource-srcUbuntutrusty*
Qtbase-opensource-srcUbuntuupstream*
Qtbase-opensource-srcUbuntuxenial*

References