Vulnerability CVE-2020-0570: Information

Description

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

Severity: HIGH (7.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Published: Sept. 14, 2020
Modified: Sept. 21, 2021
Error type identifier: CWE-426

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
qt5-3dsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1290-1246056Fixed
qt5-3dp105.12.7-alt15.15.13-alt1ALT-PU-2020-1290-1246056Fixed
qt5-3dp95.12.7-alt15.12.12-alt1ALT-PU-2020-1374-1246630Fixed
qt5-3dc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1290-1246056Fixed
qt5-3dc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1374-1246630Fixed
qt5-basesisyphus5.12.6-alt35.15.13-alt2ALT-PU-2020-1143-1245600Fixed
qt5-basep105.12.6-alt35.15.13-alt1ALT-PU-2020-1143-1245600Fixed
qt5-basep95.12.6-alt35.12.12-alt1ALT-PU-2020-1170-1245601Fixed
qt5-basec10f15.12.6-alt35.15.8-alt2ALT-PU-2020-1143-1245600Fixed
qt5-basec9f25.12.6-alt35.12.9-alt1ALT-PU-2020-1170-1245601Fixed
qt5-canvas3dp95.12.7-alt15.12.12-alt1ALT-PU-2020-1373-1246630Fixed
qt5-canvas3dc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1373-1246630Fixed
qt5-chartssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1293-1246056Fixed
qt5-chartsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1293-1246056Fixed
qt5-chartsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1377-1246630Fixed
qt5-chartsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1293-1246056Fixed
qt5-chartsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1377-1246630Fixed
qt5-connectivitysisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1283-1246056Fixed
qt5-connectivityp105.12.7-alt15.15.13-alt1ALT-PU-2020-1283-1246056Fixed
qt5-connectivityp95.12.7-alt15.12.12-alt1ALT-PU-2020-1366-1246630Fixed
qt5-connectivityc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1283-1246056Fixed
qt5-connectivityc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1366-1246630Fixed
qt5-datavis3dsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1295-1246056Fixed
qt5-datavis3dp105.12.7-alt15.15.13-alt1ALT-PU-2020-1295-1246056Fixed
qt5-datavis3dp95.12.7-alt15.12.12-alt1ALT-PU-2020-1379-1246630Fixed
qt5-datavis3dc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1295-1246056Fixed
qt5-datavis3dc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1379-1246630Fixed
qt5-declarativesisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1268-1246056Fixed
qt5-declarativep105.12.7-alt15.15.13-alt1ALT-PU-2020-1268-1246056Fixed
qt5-declarativep95.12.7-alt15.12.12-alt1ALT-PU-2020-1351-1246630Fixed
qt5-declarativec10f15.12.7-alt15.15.8-alt2ALT-PU-2020-1268-1246056Fixed
qt5-declarativec9f25.12.7-alt15.12.9-alt2ALT-PU-2020-1351-1246630Fixed
qt5-docsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1287-1246056Fixed
qt5-docp105.12.7-alt15.15.13-alt1ALT-PU-2020-1287-1246056Fixed
qt5-docp95.12.7-alt15.12.12-alt1ALT-PU-2020-1370-1246630Fixed
qt5-docc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1287-1246056Fixed
qt5-docc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1370-1246630Fixed
qt5-gamepadsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1296-1246056Fixed
qt5-gamepadp105.12.7-alt15.15.13-alt1ALT-PU-2020-1296-1246056Fixed
qt5-gamepadp95.12.7-alt15.12.12-alt1ALT-PU-2020-1380-1246630Fixed
qt5-gamepadc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1296-1246056Fixed
qt5-gamepadc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1380-1246630Fixed
qt5-graphicaleffectssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1286-1246056Fixed
qt5-graphicaleffectsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1286-1246056Fixed
qt5-graphicaleffectsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1369-1246630Fixed
qt5-graphicaleffectsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1286-1246056Fixed
qt5-graphicaleffectsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1369-1246630Fixed
qt5-imageformatssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1280-1246056Fixed
qt5-imageformatsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1280-1246056Fixed
qt5-imageformatsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1363-1246630Fixed
qt5-imageformatsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1280-1246056Fixed
qt5-imageformatsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1363-1246630Fixed
qt5-locationsisyphus5.12.7-alt15.15.13-alt1.1ALT-PU-2020-1274-1246056Fixed
qt5-locationp105.12.7-alt15.15.13-alt1ALT-PU-2020-1274-1246056Fixed
qt5-locationp95.12.7-alt15.12.12-alt1ALT-PU-2020-1357-1246630Fixed
qt5-locationc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1274-1246056Fixed
qt5-locationc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1357-1246630Fixed
qt5-multimediasisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1272-1246056Fixed
qt5-multimediap105.12.7-alt15.15.13-alt1ALT-PU-2020-1272-1246056Fixed
qt5-multimediap95.12.7-alt15.12.12-alt1ALT-PU-2020-1355-1246630Fixed
qt5-multimediac10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1272-1246056Fixed
qt5-multimediac9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1355-1246630Fixed
qt5-networkauthsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1298-1246056Fixed
qt5-networkauthp105.12.7-alt15.15.13-alt1ALT-PU-2020-1298-1246056Fixed
qt5-networkauthp95.12.7-alt15.12.12-alt1ALT-PU-2020-1382-1246630Fixed
qt5-networkauthc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1298-1246056Fixed
qt5-networkauthc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1382-1246630Fixed
qt5-quickcontrolssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1277-1246056Fixed
qt5-quickcontrolsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1277-1246056Fixed
qt5-quickcontrolsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1360-1246630Fixed
qt5-quickcontrolsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1277-1246056Fixed
qt5-quickcontrolsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1360-1246630Fixed
qt5-quickcontrols2sisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1282-1246056Fixed
qt5-quickcontrols2p105.12.7-alt15.15.13-alt1ALT-PU-2020-1282-1246056Fixed
qt5-quickcontrols2p95.12.7-alt15.12.12-alt1ALT-PU-2020-1365-1246630Fixed
qt5-quickcontrols2c10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1282-1246056Fixed
qt5-quickcontrols2c9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1365-1246630Fixed
qt5-remoteobjectssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1556-1248426Fixed
qt5-remoteobjectsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1556-1248426Fixed
qt5-remoteobjectsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1556-1248426Fixed
qt5-remoteobjectsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1556-1248426Fixed
qt5-scriptsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1278-1246056Fixed
qt5-scriptp105.12.7-alt15.15.13-alt1ALT-PU-2020-1278-1246056Fixed
qt5-scriptp95.12.7-alt15.12.12-alt1ALT-PU-2020-1361-1246630Fixed
qt5-scriptc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1278-1246056Fixed
qt5-scriptc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1361-1246630Fixed
qt5-scxmlsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1292-1246056Fixed
qt5-scxmlp105.12.7-alt15.15.13-alt1ALT-PU-2020-1292-1246056Fixed
qt5-scxmlp95.12.7-alt15.12.12-alt1ALT-PU-2020-1376-1246630Fixed
qt5-scxmlc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1292-1246056Fixed
qt5-scxmlc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1376-1246630Fixed
qt5-sensorssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1275-1246056Fixed
qt5-sensorsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1275-1246056Fixed
qt5-sensorsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1358-1246630Fixed
qt5-sensorsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1275-1246056Fixed
qt5-sensorsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1358-1246630Fixed
qt5-serialbussisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1284-1246056Fixed
qt5-serialbusp105.12.7-alt15.15.13-alt1ALT-PU-2020-1284-1246056Fixed
qt5-serialbusp95.12.7-alt15.12.12-alt1ALT-PU-2020-1367-1246630Fixed
qt5-serialbusc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1284-1246056Fixed
qt5-serialbusc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1367-1246630Fixed
qt5-serialportsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1273-1246056Fixed
qt5-serialportp105.12.7-alt15.15.13-alt1ALT-PU-2020-1273-1246056Fixed
qt5-serialportp95.12.7-alt15.12.12-alt1ALT-PU-2020-1356-1246630Fixed
qt5-serialportc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1273-1246056Fixed
qt5-serialportc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1356-1246630Fixed
qt5-speechsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1294-1246056Fixed
qt5-speechp105.12.7-alt15.15.13-alt1ALT-PU-2020-1294-1246056Fixed
qt5-speechp95.12.7-alt15.12.12-alt1ALT-PU-2020-1378-1246630Fixed
qt5-speechc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1294-1246056Fixed
qt5-speechc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1378-1246630Fixed
qt5-svgsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1281-1246056Fixed
qt5-svgp105.12.7-alt15.15.13-alt1ALT-PU-2020-1281-1246056Fixed
qt5-svgp95.12.7-alt15.12.12-alt1ALT-PU-2020-1364-1246630Fixed
qt5-svgc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1281-1246056Fixed
qt5-svgc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1364-1246630Fixed
qt5-toolssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1270-1246056Fixed
qt5-toolsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1270-1246056Fixed
qt5-toolsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1353-1246630Fixed
qt5-toolsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1270-1246056Fixed
qt5-toolsc9f25.12.7-alt15.12.9-alt2ALT-PU-2020-1353-1246630Fixed
qt5-translationssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1285-1246056Fixed
qt5-translationsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1285-1246056Fixed
qt5-translationsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1368-1246630Fixed
qt5-translationsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1285-1246056Fixed
qt5-translationsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1368-1246630Fixed
qt5-virtualkeyboardsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1291-1246056Fixed
qt5-virtualkeyboardp105.12.7-alt15.15.13-alt1ALT-PU-2020-1291-1246056Fixed
qt5-virtualkeyboardp95.12.7-alt15.12.12-alt1ALT-PU-2020-1375-1246630Fixed
qt5-virtualkeyboardc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1291-1246056Fixed
qt5-virtualkeyboardc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1375-1246630Fixed
qt5-waylandsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1288-1246056Fixed
qt5-waylandp105.12.7-alt15.15.13-alt1ALT-PU-2020-1288-1246056Fixed
qt5-waylandp95.12.7-alt15.12.12-alt1ALT-PU-2020-1371-1246630Fixed
qt5-waylandc10f15.12.7-alt15.15.8-alt2ALT-PU-2020-1288-1246056Fixed
qt5-waylandc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1371-1246630Fixed
qt5-webchannelsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1276-1246056Fixed
qt5-webchannelp105.12.7-alt15.15.13-alt1ALT-PU-2020-1276-1246056Fixed
qt5-webchannelp95.12.7-alt15.12.12-alt1ALT-PU-2020-1359-1246630Fixed
qt5-webchannelc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1276-1246056Fixed
qt5-webchannelc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1359-1246630Fixed
qt5-webenginesisyphus5.12.7-alt15.15.16-alt5ALT-PU-2020-1289-1246056Fixed
qt5-webenginep105.12.7-alt15.15.16-alt4ALT-PU-2020-1289-1246056Fixed
qt5-webenginep95.12.7-alt15.12.12-alt1ALT-PU-2020-1372-1246630Fixed
qt5-webenginec10f15.12.7-alt15.15.13-alt1ALT-PU-2020-1289-1246056Fixed
qt5-webenginec9f25.12.7-alt15.12.9-alt2.c9.1ALT-PU-2020-1372-1246630Fixed
qt5-websocketssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1271-1246056Fixed
qt5-websocketsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1271-1246056Fixed
qt5-websocketsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1354-1246630Fixed
qt5-websocketsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1271-1246056Fixed
qt5-websocketsc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1354-1246630Fixed
qt5-webviewsisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1297-1246056Fixed
qt5-webviewp105.12.7-alt15.15.13-alt1ALT-PU-2020-1297-1246056Fixed
qt5-webviewp95.12.7-alt15.12.12-alt1ALT-PU-2020-1381-1246630Fixed
qt5-webviewc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1297-1246056Fixed
qt5-webviewc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1381-1246630Fixed
qt5-x11extrassisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1279-1246056Fixed
qt5-x11extrasp105.12.7-alt15.15.13-alt1ALT-PU-2020-1279-1246056Fixed
qt5-x11extrasp95.12.7-alt15.12.12-alt1ALT-PU-2020-1362-1246630Fixed
qt5-x11extrasc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1279-1246056Fixed
qt5-x11extrasc9f25.12.7-alt15.12.9-alt1ALT-PU-2020-1362-1246630Fixed
qt5-xmlpatternssisyphus5.12.7-alt15.15.13-alt1ALT-PU-2020-1269-1246056Fixed
qt5-xmlpatternsp105.12.7-alt15.15.13-alt1ALT-PU-2020-1269-1246056Fixed
qt5-xmlpatternsp95.12.7-alt15.12.12-alt1ALT-PU-2020-1352-1246630Fixed
qt5-xmlpatternsc10f15.12.7-alt15.15.8-alt1ALT-PU-2020-1269-1246056Fixed
qt5-xmlpatternsc9f25.12.7-alt15.12.9-alt2ALT-PU-2020-1352-1246630Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
      Start including
      5.10.0
      End excliding
      5.12.7

      cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
      Start including
      5.13.0
      End excliding
      5.14.0

      cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
      End excliding
      5.9.10

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*