CVE-2022-25255: High severity trolltech qt vulnerability
Published Feb 16, 2022
·Updated
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
Affected Software
4 affected components
Qt QT>=5.9.0<5.15.9
Qt QT>=6.0.0<6.2.4
Linux Linux kernel
Opengroup Unix
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 16, 2022
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25255?
CVE-2022-25255 is a vulnerability in Qt library versions 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX operating systems.
2
How does CVE-2022-25255 affect Qt?
CVE-2022-25255 allows QProcess in Qt to execute a binary from the current working directory when not found in the PATH.
3
What is the severity of CVE-2022-25255?
The severity of CVE-2022-25255 is high with a CVSS score of 7.8.
4
Which versions of Qt are affected by CVE-2022-25255?
Qt versions 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 are affected by CVE-2022-25255.
5
How can I mitigate CVE-2022-25255?
To mitigate CVE-2022-25255, it is recommended to upgrade to Qt version 5.15.9 or 6.2.4 or later.