当前位置:网站首页>安全提示:Qt中的FreeType
安全提示:Qt中的FreeType
2022-07-30 09:57:00 【꧁白杨树下꧂】
Security advisory: FreeType in Qt
安全提示:Qt中的FreeType
Wednesday July 27, 2022 by Andy Shaw | Comments
2022年7月27日星期三,Andy Shaw评论
There have been three vulnerabilities found in FreeType recently and they have been assigned the CVE ids CVE-2022-27404, CVE-2022-27405, CVE-2022-27406. This has been fixed in the latest version of FreeType – v2.12.1
最近在FreeType中发现了三个漏洞,它们被指定为CVE ID CVE-2022-27404、CVE-2022-27405、CVE-2022-27406。这已在最新版本的FreeType–v2.12.1中修复
These effects configurations of Qt that have been built against the bundled version of FreeType. If you are using a pre-built version of Qt then this will be using the bundled version of FreeType by default, otherwise you will be using the system version by default, in which case you should check if the system needs to be updated or not. If the system needs to be updated, then updating it is enough to solve the issue. There is no need to rebuild Qt in that case.
这些影响了针对FreeType捆绑版本构建的Qt配置。如果您使用的是Qt的预构建版本,那么默认情况下将使用FreeType的捆绑版本,否则默认情况下将使用系统版本,在这种情况下,您应该检查是否需要更新系统。如果需要更新系统,那么更新它就足以解决问题。在这种情况下,没有必要重建Qt。
Solution: To work-around it, then update your system version of FreeType to at least v2.12.1 and reconfigure and build Qt to use the system version of FreeType. Or apply the following patch or update to Qt 6.3.2 when it is released.
解决方案:解决这个问题,然后将FreeType的系统版本更新到至少v2.12.1,并重新配置和构建Qt以使用FreeType的系统版本。或者在Qt 6.3.2发布时,对其应用以下补丁或更新。
Patches:
修补程序:
dev: https://codereview.qt-project.org/c/qt/qtbase/+/422316
6.4: https://codereview.qt-project.org/c/qt/qtbase/+/423390
6.3: https://codereview.qt-project.org/c/qt/qtbase/+/423391 or https://download.qt.io/official_releases/qt/6.3/CVE-2022-27404-27405-27406-qtbase-6.3.diff
6.2: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423393 or https://download.qt.io/official_releases/qt/6.2/CVE-2022-27404-27405-27406-qtbase-6.2.diff
5.15: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423394 or https://download.qt.io/official_releases/qt/5.15/CVE-2022-27404-27405-27406-qtbase-5.15.diff
边栏推荐
- Security Thought Project Summary
- EViews 12.0软件安装包下载及安装教程
- 神秘的APT攻击
- Do you really understand the 5 basic data structures of Redis?
- [AGC] Growth Service 2 - In-App Message Example
- Re19: Read the paper Paragraph-level Rationale Extraction through Regularization: A case study on European Court
- 阿里云OSS对象存储
- Re17: Read the paper Challenges for Information Extraction from Dialogue in Criminal Law
- Linux内核设计与实现(十)| 页高速缓存和页回写
- 数据库脏读、不可重复读、幻读以及对应的隔离级别
猜你喜欢

SST-Calib: A lidar-visual extrinsic parameter calibration method combining semantics and VO for spatiotemporal synchronization calibration (ITSC 2022)
![[Deep Learning] (Problem Record) <What do I get by calculating the gradient of a variable> - Linear Regression - Small Batch Stochastic Gradient Descent](/img/28/834aac16859fd26ab69de30f5fed55.png)
[Deep Learning] (Problem Record)
- Linear Regression - Small Batch Stochastic Gradient Descent 
Re20:读论文 What About the Precedent: An Information-Theoretic Analysis of Common Law

Re18:读论文 GCI Everything Has a Cause: Leveraging Causal Inference in Legal Text Analysis

梅科尔工作室-看鸿蒙设备开发实战笔记七——网络应用开发

一个近乎完美的 Unity 全平台热更方案

Study Notes 11--Direct Construction of Local Trajectories

Re19: Read the paper Paragraph-level Rationale Extraction through Regularization: A case study on European Court

hcip06 ospf special area comprehensive experiment

(文字)无框按钮设置
随机推荐
【HMS core】【FAQ】HMS Toolkit典型问题合集1
hcip06 ospf special area comprehensive experiment
MFCC to audio, the effect should not be too funny >V
Verilog之数码管译码
606. Create a string from a binary tree (video explanation!!!)
Study Notes 10--Main Methods of Local Trajectory Generation
Basemap和Seaborn
The method of parameter passing
Meikle Studio - see the actual combat notes of Hongmeng equipment development five - drive subsystem development
[AGC] Growth Service 2 - In-App Message Example
论文阅读:SegFormer: Simple and Efficient Design for Semantic Segmentation with Transformers
北京突然宣布,元宇宙重大消息
Re19:读论文 Paragraph-level Rationale Extraction through Regularization: A case study on European Court
容器技术 -- 简单了解 Kubernetes 的对象
Meikle Studio - see the actual combat notes of Hongmeng device development 4 - kernel development
Re18: Read the paper GCI Everything Has a Cause: Leveraging Causal Inference in Legal Text Analysis
Meikle Studio-Look at Hongmeng Device Development Practical Notes 7-Network Application Development
ospf2 two-point two-way republish (question 2)
Security思想项目总结
梅科尔工作室-看鸿蒙设备开发实战笔记七——网络应用开发