Fedora 40 update for deepin-qt5integration, deepin-qt5platform-plugins, dwayland, fcitx-qt5, fcitx5-qt, gammaray, kddockwidgets, keepassxc, kf5-akonadi-server, kf5-frameworkintegration, kf5-kwayland, plasma-integration, python-qt5, qadwaitadecorations, qg



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2024-36048
CWE-ID CWE-337
Exploitation vector Network
Public exploit N/A
Vulnerable software
Fedora
Operating systems & Components / Operating system

qt5ct
Operating systems & Components / Operating system package or component

qt5-qtxmlpatterns
Operating systems & Components / Operating system package or component

qt5-qtx11extras
Operating systems & Components / Operating system package or component

qt5-qtwebview
Operating systems & Components / Operating system package or component

qt5-qtwebsockets
Operating systems & Components / Operating system package or component

qt5-qtwebkit
Operating systems & Components / Operating system package or component

qt5-qtwebengine
Operating systems & Components / Operating system package or component

qt5-qtwebchannel
Operating systems & Components / Operating system package or component

qt5-qtwayland
Operating systems & Components / Operating system package or component

qt5-qtvirtualkeyboard
Operating systems & Components / Operating system package or component

qt5-qttranslations
Operating systems & Components / Operating system package or component

qt5-qttools
Operating systems & Components / Operating system package or component

qt5-qtsvg
Operating systems & Components / Operating system package or component

qt5-qtspeech
Operating systems & Components / Operating system package or component

qt5-qtserialport
Operating systems & Components / Operating system package or component

qt5-qtserialbus
Operating systems & Components / Operating system package or component

qt5-qtsensors
Operating systems & Components / Operating system package or component

qt5-qtscxml
Operating systems & Components / Operating system package or component

qt5-qtscript
Operating systems & Components / Operating system package or component

qt5-qtremoteobjects
Operating systems & Components / Operating system package or component

qt5-qtquickcontrols2
Operating systems & Components / Operating system package or component

qt5-qtquickcontrols
Operating systems & Components / Operating system package or component

qt5-qtnetworkauth
Operating systems & Components / Operating system package or component

qt5-qtmultimedia
Operating systems & Components / Operating system package or component

qt5-qtlocation
Operating systems & Components / Operating system package or component

qt5-qtimageformats
Operating systems & Components / Operating system package or component

qt5-qtgraphicaleffects
Operating systems & Components / Operating system package or component

qt5-qtgamepad
Operating systems & Components / Operating system package or component

qt5-qtdoc
Operating systems & Components / Operating system package or component

qt5-qtdeclarative
Operating systems & Components / Operating system package or component

qt5-qtdatavis3d
Operating systems & Components / Operating system package or component

qt5-qtconnectivity
Operating systems & Components / Operating system package or component

qt5-qtcharts
Operating systems & Components / Operating system package or component

qt5-qtbase
Operating systems & Components / Operating system package or component

qt5-qt3d
Operating systems & Components / Operating system package or component

qt5
Operating systems & Components / Operating system package or component

qgnomeplatform
Operating systems & Components / Operating system package or component

qadwaitadecorations
Operating systems & Components / Operating system package or component

python-qt5
Operating systems & Components / Operating system package or component

plasma-integration
Operating systems & Components / Operating system package or component

kf5-kwayland
Operating systems & Components / Operating system package or component

kf5-frameworkintegration
Operating systems & Components / Operating system package or component

kf5-akonadi-server
Operating systems & Components / Operating system package or component

keepassxc
Operating systems & Components / Operating system package or component

kddockwidgets
Operating systems & Components / Operating system package or component

gammaray
Operating systems & Components / Operating system package or component

fcitx5-qt
Operating systems & Components / Operating system package or component

fcitx-qt5
Operating systems & Components / Operating system package or component

dwayland
Operating systems & Components / Operating system package or component

deepin-qt5platform-plugins
Operating systems & Components / Operating system package or component

deepin-qt5integration
Operating systems & Components / Operating system package or component

Vendor Fedoraproject

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Predictable Seed in Pseudo-Random Number Generator (PRNG)

EUVDB-ID: #VU89843

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2024-36048

CWE-ID: CWE-337 - Predictable Seed in Pseudo-Random Number Generator (PRNG)

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to QAbstractOAuth in Qt Network Authorization uses only time to seed the PRNG. A remote attacker can guess authorization tokens and bypass authentication.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Fedora: 40

qt5ct: before 1.1-24.fc40

qt5-qtxmlpatterns: before 5.15.14-1.fc40

qt5-qtx11extras: before 5.15.14-1.fc40

qt5-qtwebview: before 5.15.14-1.fc40

qt5-qtwebsockets: before 5.15.14-1.fc40

qt5-qtwebkit: before 5.212.0-0.87alpha4.fc40

qt5-qtwebengine: before 5.15.16-6.fc40

qt5-qtwebchannel: before 5.15.14-1.fc40

qt5-qtwayland: before 5.15.14-1.fc40

qt5-qtvirtualkeyboard: before 5.15.14-1.fc40

qt5-qttranslations: before 5.15.14-1.fc40

qt5-qttools: before 5.15.14-1.fc40

qt5-qtsvg: before 5.15.14-1.fc40

qt5-qtspeech: before 5.15.14-1.fc40

qt5-qtserialport: before 5.15.14-1.fc40

qt5-qtserialbus: before 5.15.14-1.fc40

qt5-qtsensors: before 5.15.14-1.fc40

qt5-qtscxml: before 5.15.14-1.fc40

qt5-qtscript: before 5.15.14-1.fc40

qt5-qtremoteobjects: before 5.15.14-1.fc40

qt5-qtquickcontrols2: before 5.15.14-1.fc40

qt5-qtquickcontrols: before 5.15.14-1.fc40

qt5-qtnetworkauth: before 5.15.14-1.fc40

qt5-qtmultimedia: before 5.15.14-1.fc40

qt5-qtlocation: before 5.15.14-1.fc40

qt5-qtimageformats: before 5.15.14-1.fc40

qt5-qtgraphicaleffects: before 5.15.14-1.fc40

qt5-qtgamepad: before 5.15.14-1.fc40

qt5-qtdoc: before 5.15.14-1.fc40

qt5-qtdeclarative: before 5.15.14-1.fc40

qt5-qtdatavis3d: before 5.15.14-1.fc40

qt5-qtconnectivity: before 5.15.14-1.fc40

qt5-qtcharts: before 5.15.14-1.fc40

qt5-qtbase: before 5.15.14-1.fc40

qt5-qt3d: before 5.15.14-1.fc40

qt5: before 5.15.14-1.fc40

qgnomeplatform: before 0.9.2-15.fc40

qadwaitadecorations: before 0.1.5-4.fc40

python-qt5: before 5.15.10-6.fc40

plasma-integration: before 6.0.5-2.fc40

kf5-kwayland: before 5.115.0-3.fc40

kf5-frameworkintegration: before 5.115.0-3.fc40

kf5-akonadi-server: before 23.08.5-3.fc40

keepassxc: before 2.7.8-2.fc40

kddockwidgets: before 1.7.0-10.fc40

gammaray: before 3.0.0-6.fc40

fcitx5-qt: before 5.1.6-3.fc40

fcitx-qt5: before 1.2.6-21.fc40

dwayland: before 5.25.0-6.fc40

deepin-qt5platform-plugins: before 5.6.12-7.fc40

deepin-qt5integration: before 5.6.11-7.fc40

CPE2.3 External links

https://bodhi.fedoraproject.org/updates/FEDORA-2024-2e27372d4c


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###