UBUNTU-CVE-2022-25255
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-25255
UBUNTU-CVE-2022-25255
Summary:
Details: In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
References: https://ubuntu.com/security/CVE-2022-25255, https://download.qt.io/official_releases/qt/6.2/qprocess6-2.diff, https://codereview.qt-project.org/c/qt/qtbase/+/393113, https://download.qt.io/official_releases/qt/5.15/qprocess5-15.diff, https://codereview.qt-project.org/c/qt/qtbase/+/396020, https://codereview.qt-project.org/c/qt/qtbase/+/394914, https://www.cve.org/CVERecord?id=CVE-2022-25255, https://ubuntu.com/security/notices/USN-8076-1
Affected packages
Package
Name: qtbase-opensource-src
Purl: pkg:deb/ubuntu/qtbase-opensource-src?arch=source&distro=esm-apps%2Ffocal
Affected ranges
Type: ECOSYSTEM
Events:
