CVE-2020-0570

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
References
Link Resource
https://bugreports.qt.io/browse/QTBUG-81272 Exploit Patch Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1800604 Issue Tracking Patch Third Party Advisory
https://lists.qt-project.org/pipermail/development/2020-January/038534.html Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

History

21 Sep 2021, 17:58

Type Values Removed Values Added
References (CONFIRM) https://bugreports.qt.io/browse/QTBUG-81272 - (CONFIRM) https://bugreports.qt.io/browse/QTBUG-81272 - Exploit, Patch, Vendor Advisory
References (CONFIRM) https://lists.qt-project.org/pipermail/development/2020-January/038534.html - (CONFIRM) https://lists.qt-project.org/pipermail/development/2020-January/038534.html - Mailing List, Vendor Advisory

21 Aug 2021, 17:15

Type Values Removed Values Added
References
  • (CONFIRM) https://bugreports.qt.io/browse/QTBUG-81272 -
  • (CONFIRM) https://lists.qt-project.org/pipermail/development/2020-January/038534.html -

Information

Published : 2020-09-14 19:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-0570

Mitre link : CVE-2020-0570

CVE.ORG link : CVE-2020-0570


JSON object : View

Products Affected

qt

  • qt

redhat

  • enterprise_linux
CWE
CWE-426

Untrusted Search Path