Executive Summary
Summary | |
---|---|
Title | Qt allows for privilege escalation due to hard-coding of qt_prfxpath value |
Informations | |||
---|---|---|---|
Name | VU#411271 | First vendor Publication | 2022-04-28 |
Vendor | VU-CERT | Last vendor Modification | 2022-04-29 |
Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H | |||
---|---|---|---|
Overall CVSS Score | 8.2 | ||
Base Score | 8.2 | Environmental Score | 8.2 |
impact SubScore | 6 | Temporal Score | 8.2 |
Exploitabality Sub Score | 1.5 | ||
Attack Vector | Local | Attack Complexity | Low |
Privileges Required | High | User Interaction | None |
Scope | Changed | Confidentiality Impact | High |
Integrity Impact | High | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : | |||
---|---|---|---|
Cvss Base Score | N/A | Attack Range | N/A |
Cvss Impact Score | N/A | Attack Complexity | N/A |
Cvss Expoit Score | N/A | Authentication | N/A |
Calculate full CVSS 2.0 Vectors scores |
Detail
OverviewPrior to version 5.14, Qt hard-codes the DescriptionPrior to version 5.14, Qt hard-codes the In 2015, a patch was made to windeployqt to strip out any existing ImpactBy placing a file in an appropriate location on a Windows system, an unprivileged attacker may be able to execute arbitrary code with the privileges of the software that uses Qt. SolutionApply an updateThis issue is addressed in Qt 5.14. Starting with this version, Qt no longer hard-codes the Run windeployqt to prepare Windows Qt software for deploymentThe windeployqt utility will replace the AcknowledgementsThis document was written by Will Dormann. |
Original Source
Url : https://kb.cert.org/vuls/id/411271 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-787 | Out-of-bounds Write (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 1 |
Alert History
Date | Informations |
---|---|
2022-10-05 02:19:01 |
|
2022-10-05 00:34:46 |
|
2022-04-29 21:17:42 |
|
2022-04-28 17:17:43 |
|