PT-2021-11070 · Qt Company+1 · Qt+1

Published

2021-08-09

·

Updated

2025-01-29

·

CVE-2020-24741

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Qt versions 5.12.7 and 5.14.1
Description: An issue has been fixed where QLibrary attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
Recommendations: For Qt version 5.12.7, update to a version where this issue is fixed. For Qt version 5.14.1, update to a version where this issue is fixed.

Fix

Related Identifiers

CVE-2020-24741
MGASA-2021-0510
ROSA-SA-2025-2677
SUSE-SU-2021:3268-1
SUSE-SU-2021:3269-1
SUSE-SU-2021_3268-1
SUSE-SU-2021_3269-1
SUSE-SU-2023:2816-1
SUSE-SU-2023_2816-1

Affected Products

Qt
Suse