An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
References
Link Resource
https://codereview.qt-project.org/c/qt/qtbase/+/280730 Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-09T21:18:27

Updated: 2021-08-09T21:18:27

Reserved: 2020-08-28T00:00:00


Link: CVE-2020-24742

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-08-09T22:15:08.607

Modified: 2021-08-19T13:51:31.047


Link: CVE-2020-24742

JSON object: View

cve-icon Redhat Information

No data.