CVE-2020-0570
Summary
| CVE | CVE-2020-0570 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-14 19:15:00 UTC |
| Updated | 2021-09-21 17:58:00 UTC |
| Description | Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [QTBUG-81272] Qt tries to load invalid library from CWD - Qt Bug Tracker |
CONFIRM |
bugreports.qt.io |
|
| 1800604 – (CVE-2020-0570) CVE-2020-0570 qt: files placed by attacker can influence the working directory and lead to malicious code execution |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [Development] New Qt vulnerabilities |
CONFIRM |
lists.qt-project.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377535 Alibaba Cloud Linux Security Update for qt5-qtbase (ALINUX2-SA-2020:0153)
- 670938 EulerOS Security Update for qt (EulerOS-SA-2020-2393)
- 900114 CBL-Mariner Linux Security Update for qt5-qtbase 5.12.5
- 901445 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtsvg (6834-1)
- 902909 Common Base Linux Mariner (CBL-Mariner) Security Update for qt5-qtbase (4690)
- 940264 AlmaLinux Security Update for qt5-qtbase and qt5-qtwebsockets (ALSA-2020:4690)
- 960823 Rocky Linux Security Update for qt5-qtbase and qt5-qtwebsockets (RLSA-2020:4690)