CVE-2020-12267: Use After Free
Published Apr 27, 2020
·Updated
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
Affected Software
1 affected component
Qt QT=5.14.1
Remediation
Patch Available
Event History
Apr 27, 2020
CVE Published
via MITRE·01:31 AM
Data Sourced
via MITRE·01:31 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-12267.
2
What is the severity of CVE-2020-12267?
The severity of CVE-2020-12267 is critical (9.8).
3
Which software versions are affected by CVE-2020-12267?
CVE-2020-12267 affects Qt version 5.14.1.
4
What is the description of CVE-2020-12267?
CVE-2020-12267 is a use-after-free vulnerability related to QTextMarkdownImporter::insertBlock in Qt before version 5.14.2.
5
How can I mitigate CVE-2020-12267?
To mitigate CVE-2020-12267, update Qt to version 5.14.2 or later.