CVE-2024-36048: Critical severity Qt Qt Network Authorization vulnerability
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36048?
CVE-2024-36048 is considered a medium-severity vulnerability due to potential predictability in generated values.
How do I fix CVE-2024-36048?
To fix CVE-2024-36048, update your Qt Network Authorization to versions 5.15.17, 6.2.13, or later versions after 6.5.6 or 6.7.1.
What impact does CVE-2024-36048 have on applications?
CVE-2024-36048 may allow attackers to predict random values, potentially compromising security features reliant on randomness.
Is my Qt version affected by CVE-2024-36048?
Qt versions prior to 5.15.17, 6.x versions before 6.2.13, and specific 6.3.x and 6.6.x versions are affected by CVE-2024-36048.
When was CVE-2024-36048 disclosed?
CVE-2024-36048 was disclosed following an issue identified in the seeding method of the pseudorandom number generator in specific Qt versions.