qt: QLibrary loads libraries relative to CWD which could result in arbitrary code execution
Published Aug 9, 2021
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-0570. Reason: This candidate is a duplicate of CVE-2020-0570. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2020-0570 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 6
qt
Out of support scope
Red Hat Enterprise Linux 6
qt3
Not affected
Red Hat Enterprise Linux 7
qt
Out of support scope
Red Hat Enterprise Linux 7
qt3
Not affected
Red Hat Enterprise Linux 8
qt5-qtbase
Not affected
Red Hat Enterprise Linux 9
qt5-qtbase
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | qt | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | qt3 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qt | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | qt3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | qt5-qtbase | Not affected | n/a |
| Red Hat Enterprise Linux 9 | qt5-qtbase | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2020-24741 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1993132 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-17452 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-24741
- https://www.cve.org/CVERecord?id=CVE-2020-24741
Change history (0)
No recorded changes yet.
CISA Vulnrichment
No data
GitHub
No data