First published: Mon Aug 09 2021(Updated: )
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | >=5.6.0<5.12.7 | |
Qt Qt | >=5.13.0<=5.13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-24742.
The severity of CVE-2020-24742 is high (7.8).
The affected software for CVE-2020-24742 is Qt versions 5.6.0 to 5.12.7 and Qt versions 5.13.0 to 5.13.2.
An attacker can exploit CVE-2020-24742 by crafting malicious files that are loaded by QPluginLoader, allowing them to execute arbitrary code.
Yes, a fix has been released in Qt version 5.14.0 to mitigate CVE-2020-24742.