CVE-2024-36048

EUVD-2024-35852
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
qtqt
𝑥
< 5.15.17
qtqt
6.0.0 ≤
𝑥
< 6.2.13
qtqt
6.3.0 ≤
𝑥
< 6.5.6
qtqt
6.6.0 ≤
𝑥
< 6.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
qt6-networkauth
bookworm
ignored
bullseye
no-dsa
buster
postponed
forky
6.9.2-3
fixed
sid
6.9.2-3
fixed
trixie
6.8.2-4
fixed
qtnetworkauth-everywhere-src
bookworm
ignored
bullseye
no-dsa
buster
postponed
forky
5.15.17-2
fixed
sid
5.15.17-2
fixed
trixie
5.15.15-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qtnetworkauth-everywhere-src
focal
needs-triage
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage