CVE-2022-25255
Summary
| CVE | CVE-2022-25255 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-16 19:15:00 UTC |
| Updated | 2022-02-28 16:18:00 UTC |
| Description | In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| codereview.qt-project.org/c/qt/qtbase/+/393113 | MISC | codereview.qt-project.org | Issue Tracking, Patch, Vendor Advisory |
| codereview.qt-project.org/c/qt/qtbase/+/396020 | MISC | codereview.qt-project.org | Patch, Release Notes, Vendor Advisory |
| download.qt.io/official_releases/qt/5.15/qprocess5-15.diff | MISC | download.qt.io | Patch, Vendor Advisory |
| codereview.qt-project.org/c/qt/qtbase/+/394914 | MISC | codereview.qt-project.org | Patch, Vendor Advisory |
| download.qt.io/official_releases/qt/6.2/qprocess6-2.diff | MISC | download.qt.io | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160208 Oracle Enterprise Linux Security Update for qt5 (ELSA-2022-7482)
- 160265 Oracle Enterprise Linux Security Update for qt5 (ELSA-2022-8022)
- 183302 Debian Security Update for qtbase-opensource-src-glesqtbase-opensource-srcqt6-base (CVE-2022-25255)
- 240820 Red Hat Update for qt5 security (RHSA-2022:7482)
- 240882 Red Hat Update for qt5 (RHSA-2022:8022)
- 378754 Alibaba Cloud Linux Security Update for qt5 (ALINUX3-SA-2023:0085)
- 672080 EulerOS Security Update for qt5-qtbase (EulerOS-SA-2022-2233)
- 690797 Free Berkeley Software Distribution (FreeBSD) Security Update for qt5 (43ae57f6-92ab-11ec-81b4-2cf05d620ecc)
- 751878 SUSE Enterprise Linux Security Update for libqt5-qtbase (SUSE-SU-2022:0841-1)
- 751891 OpenSUSE Security Update for libqt5-qtbase (openSUSE-SU-2022:0841-1)
- 940747 AlmaLinux Security Update for qt5 (ALSA-2022:7482)
- 940820 AlmaLinux Security Update for qt5 (ALSA-2022:8022)
- 960331 Rocky Linux Security Update for qt5 (RLSA-2022:7482)
- 960510 Rocky Linux Security Update for qt5 (RLSA-2022:8022)