Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1800604 | patch third party advisory issue tracking |
https://bugreports.qt.io/browse/QTBUG-81272 | patch vendor advisory exploit |
https://lists.qt-project.org/pipermail/development/2020-January/038534.html | vendor advisory mailing list |