CVE-2020-24742
גבוהה 7.8
תיאור (מקור, אנגלית)
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
מוצרים מושפעים
qt: qt
קישורים
- https://codereview.qt-project.org/c/qt/qtbase/+/280730 PatchVendor Advisory
- https://codereview.qt-project.org/c/qt/qtbase/+/280730 PatchVendor Advisory