CVE-2022-25255
16.02.2022, 19:15
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.Enginsight
| Vendor | Product | Version |
|---|---|---|
| qt | qt | 5.9.0 ≤ 𝑥 < 5.15.9 |
| qt | qt | 6.0.0 ≤ 𝑥 < 6.2.4 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qt6-base |
| ||||||||||||
| qtbase-opensource-src |
| ||||||||||||
| qtbase-opensource-src-gles |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qt6-base |
| ||||||||||||||||||||
| qtbase-opensource-src |
|
References