CVE-2020-0569
published 2020-11-23CVE-2020-0569: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local…
PriorityP419medium5.7CVSS 3.1
AVAACLPRLUINSUCNINAH
EPSS
0.56%
42.5th percentile
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qtbase-opensource-src | < qtbase-opensource-src 5.12.5+dfsg-8 (bookworm) | qtbase-opensource-src 5.12.5+dfsg-8 (bookworm) |
| intel | 7265_firmware | < 21.70 | 21.70 |
| intel | ac_3165_firmware | < 21.70 | 21.70 |
| intel | ac_3168_firmware | < 21.70 | 21.70 |
| intel | ac_8260_firmware | < 21.70 | 21.70 |
| intel | ac_8265_firmware | < 21.70 | 21.70 |
| intel | ac_9260_firmware | < 21.70 | 21.70 |
| intel | ac_9461_firmware | < 21.70 | 21.70 |
| intel | ac_9462_firmware | < 21.70 | 21.70 |
| intel | ac_9560_firmware | < 21.70 | 21.70 |
| intel | ax200_firmware | < 21.70 | 21.70 |
| intel | ax201_firmware | < 21.70 | 21.70 |
| intel_proset | wireless_wifi_products_on_windows_10 | — | — |
| msrc | cbl2_qt5-qtbase_5.12.11-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_qt5-qtsvg_5.12.11-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_qt5-qtsvg_5.12.11-4_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_msrc5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
vendor_msrc·2020-11-10·CVSS 5.7
CVE-2020-0569 [MEDIUM] CWE-787 Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mar
Ubuntu
Qt vulnerabilities
vendor_ubuntu·2020-02-10·CVSS 5.5
CVE-2018-19872 [MEDIUM] Qt vulnerabilities
Title: Qt vulnerabilities
Summary: Several security issues were fixed in Qt.
It was discovered that Qt incorrectly handled certain PPM images. If a user
or automated system were tricked into opening a specially crafted PPM file,
a remote attacker could cause Qt to crash, resulting in a denial of
service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-19872)
It was discovered that Qt incorrectly handled certain text files. If a user
or automated system were tricked into opening a specially crafted text
file, a remote attacker could cause Qt to crash, resulting in a denial of
service. This issue only affected Ubuntu 19.10. (CVE-2019-18281)
It was discovered that Qt incorrectly searched for plugins in the current
working directory. An attacker could possibly use
Red Hat
qt: files placed by attacker can influence the working directory and lead to malicious code execution
vendor_redhat·2020-02-07·CVSS 5.7
CVE-2020-0569 [MEDIUM] CWE-73 qt: files placed by attacker can influence the working directory and lead to malicious code execution
qt: files placed by attacker can influence the working directory and lead to malicious code execution
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
Debian
CVE-2020-0569: qtbase-opensource-src - Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may ...
vendor_debian·2020·CVSS 5.7
CVE-2020-0569 [MEDIUM] CVE-2020-0569: qtbase-opensource-src - Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may ...
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
Scope: local
bookworm: resolved (fixed in 5.12.5+dfsg-8)
bullseye: resolved (fixed in 5.12.5+dfsg-8)
forky: resolved (fixed in 5.12.5+dfsg-8)
sid: resolved (fixed in 5.12.5+dfsg-8)
trixie: resolved (fixed in 5.12.5+dfsg-8)
GHSA
GHSA-jmp3-vh9c-94m8: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service vi
ghsa_unreviewed·2022-05-24
CVE-2020-0569 [MEDIUM] CWE-787 GHSA-jmp3-vh9c-94m8: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service vi
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
OSV
CVE-2020-0569: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service vi
osv·2020-11-23·CVSS 5.7
CVE-2020-0569 [MEDIUM] CVE-2020-0569: Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service vi
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
OSV
qtbase-opensource-src vulnerabilities
osv·2020-02-10·CVSS 5.5
CVE-2018-19872 [MEDIUM] qtbase-opensource-src vulnerabilities
qtbase-opensource-src vulnerabilities
It was discovered that Qt incorrectly handled certain PPM images. If a user
or automated system were tricked into opening a specially crafted PPM file,
a remote attacker could cause Qt to crash, resulting in a denial of
service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-19872)
It was discovered that Qt incorrectly handled certain text files. If a user
or automated system were tricked into opening a specially crafted text
file, a remote attacker could cause Qt to crash, resulting in a denial of
service. This issue only affected Ubuntu 19.10. (CVE-2019-18281)
It was discovered that Qt incorrectly searched for plugins in the current
working directory. An attacker could possibly use this issue to execute
arbitrary code. (
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id ASCII"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005162; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UPDATE"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005163; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id SELECT"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005158; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id INSERT"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005160; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id UNION SELECT"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005159; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mi
Suricata
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0569 [HIGH] ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE
ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS xNews SQL Injection Attempt -- xNews.php id DELETE"; flow:established,to_server; http.uri; content:"/xNews.php?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0569; reference:url,www.milw0rm.com/exploits/3216; classtype:web-application-attack; sid:2005161; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique
No public exploits indexed.
Bugzilla
CVE-2020-0569 qt5-qtbase: qt: files placed by attacker can influence the working directory and lead to malicious code execution [epel-6]
bugzilla·2020-03-18·CVSS 5.7
CVE-2020-0569 [MEDIUM] CVE-2020-0569 qt5-qtbase: qt: files placed by attacker can influence the working directory and lead to malicious code execution [epel-6]
CVE-2020-0569 qt5-qtbase: qt: files placed by attacker can influence the working directory and lead to malicious code execution [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2020-0569 qt5-qtbase: qt: files placed by attacker can influence the working directory and lead to malicious code execution [fedora-all]
bugzilla·2020-03-17·CVSS 5.7
CVE-2020-0569 [MEDIUM] CVE-2020-0569 qt5-qtbase: qt: files placed by attacker can influence the working directory and lead to malicious code execution [fedora-all]
CVE-2020-0569 qt5-qtbase: qt: files placed by attacker can influence the working directory and lead to malicious code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2020-0569 qt: files placed by attacker can influence the working directory and lead to malicious code execution [fedora-all]
bugzilla·2020-02-07·CVSS 5.7
CVE-2020-0569 [MEDIUM] CVE-2020-0569 qt: files placed by attacker can influence the working directory and lead to malicious code execution [fedora-all]
CVE-2020-0569 qt: files placed by attacker can influence the working directory and lead to malicious code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2020-0569 qt: files placed by attacker can influence the working directory and lead to malicious code execution
bugzilla·2020-02-07·CVSS 5.7
CVE-2020-0569 [MEDIUM] CVE-2020-0569 qt: files placed by attacker can influence the working directory and lead to malicious code execution
CVE-2020-0569 qt: files placed by attacker can influence the working directory and lead to malicious code execution
QPluginLoader would search for certain plugins first on the current working directory of the application, which allows an attacker that can place files in the file system and influence the working directory of Qt-based applications to load and execute malicious code.
Upstream Patches:
https://code.qt.io/cgit/qt/qtbase.git/commit/?id=bf131e8d2181b3404f5293546ed390999f760404
https://code.qt.io/cgit/qt/qtbase.git/commit/?id=5c4234ed958130d655df8197129806f687d4df0d
Discussion:
Created qt tracking bugs for this issue:
Affects: fedora-all [bug 1800601]
---
Created qt5 tracking bugs for this issue:
Affects: fedora-all [bug 1814163]
---
Created qt5-qtbase tracking bugs for
2020-11-23
Published