First published: Wed Feb 16 2022(Updated: )
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt Qt | >=5.9.0<5.15.9 | |
Qt Qt | >=6.0.0<6.2.4 | |
Linux Linux kernel | ||
Opengroup Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25255 is a vulnerability in Qt library versions 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX operating systems.
CVE-2022-25255 allows QProcess in Qt to execute a binary from the current working directory when not found in the PATH.
The severity of CVE-2022-25255 is high with a CVSS score of 7.8.
Qt versions 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 are affected by CVE-2022-25255.
To mitigate CVE-2022-25255, it is recommended to upgrade to Qt version 5.15.9 or 6.2.4 or later.