Path traversal in Qt - CVE-2022-25634

 

Path traversal in Qt - CVE-2022-25634

Published: August 9, 2023


Vulnerability identifier: #VU79310
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-25634
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Qt
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Pair
Dell Peripheral Manager
Software Center
MikTex
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client

How to mitigate CVE-2022-25634

Install update from vendor's website.

Qt - addressed in versions 5.15.9, 6.2.4
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
MikTex - update to 24.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Pair - update to 1.2.3
Dell Peripheral Manager - update to 1.7.3
Software Center - update to 3.0

External References

Related Security Bulletins