当前位置:网站首页>安全提示:Qt中的FreeType
安全提示:Qt中的FreeType
2022-07-30 09:57:00 【꧁白杨树下꧂】
Security advisory: FreeType in Qt
安全提示:Qt中的FreeType
Wednesday July 27, 2022 by Andy Shaw | Comments
2022年7月27日星期三,Andy Shaw评论
There have been three vulnerabilities found in FreeType recently and they have been assigned the CVE ids CVE-2022-27404, CVE-2022-27405, CVE-2022-27406. This has been fixed in the latest version of FreeType – v2.12.1
最近在FreeType中发现了三个漏洞,它们被指定为CVE ID CVE-2022-27404、CVE-2022-27405、CVE-2022-27406。这已在最新版本的FreeType–v2.12.1中修复
These effects configurations of Qt that have been built against the bundled version of FreeType. If you are using a pre-built version of Qt then this will be using the bundled version of FreeType by default, otherwise you will be using the system version by default, in which case you should check if the system needs to be updated or not. If the system needs to be updated, then updating it is enough to solve the issue. There is no need to rebuild Qt in that case.
这些影响了针对FreeType捆绑版本构建的Qt配置。如果您使用的是Qt的预构建版本,那么默认情况下将使用FreeType的捆绑版本,否则默认情况下将使用系统版本,在这种情况下,您应该检查是否需要更新系统。如果需要更新系统,那么更新它就足以解决问题。在这种情况下,没有必要重建Qt。
Solution: To work-around it, then update your system version of FreeType to at least v2.12.1 and reconfigure and build Qt to use the system version of FreeType. Or apply the following patch or update to Qt 6.3.2 when it is released.
解决方案:解决这个问题,然后将FreeType的系统版本更新到至少v2.12.1,并重新配置和构建Qt以使用FreeType的系统版本。或者在Qt 6.3.2发布时,对其应用以下补丁或更新。
Patches:
修补程序:
dev: https://codereview.qt-project.org/c/qt/qtbase/+/422316
6.4: https://codereview.qt-project.org/c/qt/qtbase/+/423390
6.3: https://codereview.qt-project.org/c/qt/qtbase/+/423391 or https://download.qt.io/official_releases/qt/6.3/CVE-2022-27404-27405-27406-qtbase-6.3.diff
6.2: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423393 or https://download.qt.io/official_releases/qt/6.2/CVE-2022-27404-27405-27406-qtbase-6.2.diff
5.15: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423394 or https://download.qt.io/official_releases/qt/5.15/CVE-2022-27404-27405-27406-qtbase-5.15.diff
边栏推荐
- If someone asks you about distributed transactions again, throw this to him
- Always remember: one day you will emerge from the chrysalis
- [100个Solidity使用技巧]1、合约重入攻击
- CVTE校招笔试题+知识点总结
- 【AGC】增长服务2-应用内消息示例
- 梅科尔工作室-看鸿蒙设备开发实战笔记四——内核开发
- 606. Create a string from a binary tree (video explanation!!!)
- Re19:读论文 Paragraph-level Rationale Extraction through Regularization: A case study on European Court
- Alibaba Cloud OSS Object Storage
- Paper reading: SegFormer: Simple and Efficient Design for Semantic Segmentation with Transformers
猜你喜欢

Redis Desktop Manager 2022.4.2 发布

Linux内核设计与实现(十)| 页高速缓存和页回写
![[Deep Learning] (Problem Record) <What do I get by calculating the gradient of a variable> - Linear Regression - Small Batch Stochastic Gradient Descent](/img/28/834aac16859fd26ab69de30f5fed55.png)
[Deep Learning] (Problem Record)
- Linear Regression - Small Batch Stochastic Gradient Descent 
spark udf accepts and handles null values.

MFCC转音频,效果不要太逗>V<!

Re15:读论文 LEVEN: A Large-Scale Chinese Legal Event Detection Dataset

【AGC】增长服务2-应用内消息示例

PyQt5 - draw text on window

Quick Start Tutorial for flyway

图像去噪——Neighbor2Neighbor: Self-Supervised Denoising from Single Noisy Images
随机推荐
js对数组操作移动进行封装
Verilog之数码管译码
idea2021+Activiti【最完整笔记一(基础使用)】
[Qualcomm][Network] 网络拨号失败和netmgrd服务分析
2022年顶会accepted papers list
MySQL | Subqueries
Js array operating mobile for encapsulation
Some commands of kubernetes
软考 系统架构设计师 简明教程 | 案例分析 | 需求分析
论文阅读:SegFormer: Simple and Efficient Design for Semantic Segmentation with Transformers
Re20:读论文的先例:普通法的信息理论分析
Re21:读论文 MSJudge Legal Judgment Prediction with Multi-Stage Case Representation Learning in the Real
时刻铭记:总有一天你将破蛹而出
flowable workflow all business concepts
图像去噪——Neighbor2Neighbor: Self-Supervised Denoising from Single Noisy Images
多线程--线程和线程池的用法
Meikle Studio-Look at the actual combat notes of Hongmeng device development six-wireless networking development
Alibaba Cloud OSS Object Storage
WARN: Establishing SSL connection without server's identity verification is not recommended when connecting to mysql
Four ways the Metaverse is changing the way humans work