f5e4100c08
Fixed the following security issue: - CVE-2020-0569: QPluginLoader in Qt versions 5.0.0 through 5.13.2 would search for certain plugins first on the current working directory of the application, which allows an attacker that can place files in the file system and influence the working directory of Qt-based applications to load and execute malicious code. This issue was verified on macOS and Linux and probably affects all other Unix operating systems. This issue does not affect Windows. - CVE-2020-0570: QLibrary in Qt versions 5.12.0 through 5.14.0, on certain x86 machines, would search for certain libraries and plugins relative to current working directory of the application, which allows an attacker that can place files in the file system and influence the working directory of Qt-based applications to load and execute malicious code. This issue was verified on Linux and probably affects all Unix operating systems, other than macOS (Darwin). This issue does not affect Windows. For details, see the advisory: https://www.openwall.com/lists/oss-security/2020/01/30/1 Signed-off-by: Peter Seiderer <ps.report@gmx.net> [Peter: extend commit message] Signed-off-by: Peter Korsgaard <peter@korsgaard.com> |
||
---|---|---|
.. | ||
5.6.3 | ||
5.12.5 | ||
Config.in | ||
qmake.conf.in | ||
qplatformdefs.h | ||
qt5base.hash | ||
qt5base.mk | ||
qt.conf.in |