当前位置:网站首页>Security tip: FreeType in Qt
Security tip: FreeType in Qt
2022-07-30 10:40:00 【꧁Under the poplar tree꧂】
Security advisory: FreeType in Qt
Security tip: FreeType in Qt
Wednesday July 27, 2022 by Andy Shaw | Comments
Wednesday, July 27, 2022, commented by Andy Shaw
There have been three vulnerabilities found in FreeType recently and they have been assigned the CVE ids CVE-2022-27404, CVE-2022-27405, CVE-2022-27406. This has been fixed in the latest version of FreeType – v2.12.1
Three vulnerabilities were recently discovered in FreeType, and they were assigned CVE IDs CVE-2022-27404, CVE-2022-27405, CVE-2022-27406.This has been fixed in the latest version of FreeType – v2.12.1
These effects configurations of Qt that have been built against the bundled version of FreeType. If you are using a pre-built version of Qt then this will be using the bundled version of FreeType by default, otherwise you will be using the systemversion by default, in which case you should check if the system needs to be updated or not. If the system needs to be updated, then updating it is enough to solve the issue. There is no need to rebuild Qt in that case.
These affect the Qt configuration built against the FreeType bundled version.If you are using a pre-built version of Qt then by default the bundled version of FreeType will be used, otherwise the system version will be used by default, in which case you should check if you need to update your system.If the system needs to be updated, then updating it is enough to fix the problem.In this case there is no need to rebuild Qt.
Solution: To work-around it, then update your system version of FreeType to at least v2.12.1 and reconfigure and build Qt to use the system version of FreeType. Or apply the following patch or update to Qt 6.3.2 whenit is released.
Solution: Fix this, then update the system version of FreeType to at least v2.12.1, and reconfigure and build Qt to use the system version of FreeType.Or apply the following patches or updates to Qt 6.3.2 when it is released.
Patches:
Patch:
dev: https://codereview.qt-project.org/c/qt/qtbase/+/422316
6.4: https://codereview.qt-project.org/c/qt/qtbase/+/423390
6.3: https://codereview.qt-project.org/c/qt/qtbase/+/423391 orhttps://download.qt.io/official_releases/qt/6.3/CVE-2022-27404-27405-27406-qtbase-6.3.diff
6.2: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423393 or https://download.qt.io/official_releases/qt/6.2/CVE-2022-27404-27405-27406-qtbase-6.2.diff
5.15: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423394 or https://download.qt.io/official_releases/qt/5.15/CVE-2022-27404-27405-27406-qtbase-5.15.diff
边栏推荐
- (C language) file operation
- OC - Manual Reference Counting Memory Management
- New in GNOME: Warn users when Secure Boot is disabled
- Always remember: one day you will emerge from the chrysalis
- Online target drone prompt.ml
- 【C和指针第七章】可变参数列表
- Multithreading--the usage of threads and thread pools
- Re20:读论文 What About the Precedent: An Information-Theoretic Analysis of Common Law
- 多线程保证单个线程开启事务并生效的方案
- mysql安装教程【安装版】
猜你喜欢

多线程--线程和线程池的用法
![[Qualcomm][Network] 网络拨号失败和netmgrd服务分析](/img/76/49054ff8c7215eca98cc479ab1d986.png)
[Qualcomm][Network] 网络拨号失败和netmgrd服务分析

Re20:读论文的先例:普通法的信息理论分析

Meikle Studio - see the actual combat notes of Hongmeng device development 4 - kernel development

JVM内存布局、类加载机制及垃圾回收机制详解

In the robot industry professionals, Mr Robot industry current situation?
![[Deep Learning] (Problem Record) <What do I get by calculating the gradient of a variable> - Linear Regression - Small Batch Stochastic Gradient Descent](/img/28/834aac16859fd26ab69de30f5fed55.png)
[Deep Learning] (Problem Record)
- Linear Regression - Small Batch Stochastic Gradient Descent 
梅科尔工作室-看鸿蒙设备开发实战笔记五——驱动子系统开发

Meikle Studio-Look at Hongmeng Device Development Practical Notes 7-Network Application Development

Online target drone prompt.ml
随机推荐
Flask's routing (app.route) detailed
Domino Server SSL Certificate Installation Guide
mysql安装教程【安装版】
【HarmonyOS】【ARK UI】HarmonyOS ets语言怎么实现双击返回键退出
The thread pool method opens the thread -- the difference between submit() and execute()
flowable工作流所有业务概念
【HMS core】【FAQ】HMS Toolkit典型问题合集1
Baidu promotion assistant encounters duplicate keywords, verification errors, how to delete redundant ones with one click
Linux内核设计与实现(十)| 页高速缓存和页回写
The creation of a large root heap (video explanation)
Security Thought Project Summary
flowable workflow all business concepts
debian10 install djando
what is this method called
Pytorch中 nn.Transformer的使用详解与Transformer的黑盒讲解
(文字)无框按钮设置
这种叫什么手法
线程池方式开启线程--submit()和execute()的区别
BERT预训练模型系列总结
Alibaba Cloud OSS Object Storage