QID 670938

QID 670938: EulerOS Security Update for qt (EulerOS-SA-2020-2393)

Qt is a software toolkit for developing applications. This package contains base tools, like string, xml, and network handling. Security Fix(es): Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.(CVE-2020-0570) An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.(CVE-2020-17507)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

An arbitrary attacker may exploit this vulnerability to compromise the system.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    The Vendor has released a security update to fix the vulnerability. For more information please visit EulerOS-SA-2020-2393 for updates and patch information

    CVEs related to QID 670938

    Software Advisories
    Advisory ID Software Component Link
    EulerOS-SA-2020-2393 EulerOS V2.0SP2 URL Logo developer.huaweicloud.com/ict/en/site-euleros/euleros/security-advisories/EulerOS-SA-2020-2393