CVE-2020-12267Use After Free in QT

CWE-416Use After Free12 documents5 sources
Severity
9.8CRITICALNVD
EPSS
0.5%
top 35.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 24

Description

setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-96rj-cc48-wqpc: setMarkdown in Qt before 52022-05-24

📋Vendor Advisories

2
Red Hat
qt: use-after-free related to QTextMarkdownImporter::insertBlock2020-04-27
Debian
CVE-2020-12267: qtbase-opensource-src - setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImp...2020

💬Community

8
Bugzilla
CVE-2020-12267 qt3: qt: use-after-free related to QTextMarkdownImporter::insertBlock [fedora-all]2020-05-19
Bugzilla
CVE-2020-12267 qt: use-after-free related to QTextMarkdownImporter::insertBlock2020-05-19
Bugzilla
CVE-2020-12267 qt5: qt: use-after-free related to QTextMarkdownImporter::insertBlock [fedora-all]2020-05-19
Bugzilla
CVE-2020-12267 qt5: qt: use-after-free related to QTextMarkdownImporter::insertBlock [fedora-all]2020-05-19
Bugzilla
CVE-2020-12267 qt: use-after-free related to QTextMarkdownImporter::insertBlock [fedora-all]2020-05-19
CVE-2020-12267 — Use After Free in QT | cvebase