当前位置:网站首页>安全提示:Qt中的FreeType
安全提示:Qt中的FreeType
2022-07-30 09:57:00 【꧁白杨树下꧂】
Security advisory: FreeType in Qt
安全提示:Qt中的FreeType
Wednesday July 27, 2022 by Andy Shaw | Comments
2022年7月27日星期三,Andy Shaw评论
There have been three vulnerabilities found in FreeType recently and they have been assigned the CVE ids CVE-2022-27404, CVE-2022-27405, CVE-2022-27406. This has been fixed in the latest version of FreeType – v2.12.1
最近在FreeType中发现了三个漏洞,它们被指定为CVE ID CVE-2022-27404、CVE-2022-27405、CVE-2022-27406。这已在最新版本的FreeType–v2.12.1中修复
These effects configurations of Qt that have been built against the bundled version of FreeType. If you are using a pre-built version of Qt then this will be using the bundled version of FreeType by default, otherwise you will be using the system version by default, in which case you should check if the system needs to be updated or not. If the system needs to be updated, then updating it is enough to solve the issue. There is no need to rebuild Qt in that case.
这些影响了针对FreeType捆绑版本构建的Qt配置。如果您使用的是Qt的预构建版本,那么默认情况下将使用FreeType的捆绑版本,否则默认情况下将使用系统版本,在这种情况下,您应该检查是否需要更新系统。如果需要更新系统,那么更新它就足以解决问题。在这种情况下,没有必要重建Qt。
Solution: To work-around it, then update your system version of FreeType to at least v2.12.1 and reconfigure and build Qt to use the system version of FreeType. Or apply the following patch or update to Qt 6.3.2 when it is released.
解决方案:解决这个问题,然后将FreeType的系统版本更新到至少v2.12.1,并重新配置和构建Qt以使用FreeType的系统版本。或者在Qt 6.3.2发布时,对其应用以下补丁或更新。
Patches:
修补程序:
dev: https://codereview.qt-project.org/c/qt/qtbase/+/422316
6.4: https://codereview.qt-project.org/c/qt/qtbase/+/423390
6.3: https://codereview.qt-project.org/c/qt/qtbase/+/423391 or https://download.qt.io/official_releases/qt/6.3/CVE-2022-27404-27405-27406-qtbase-6.3.diff
6.2: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423393 or https://download.qt.io/official_releases/qt/6.2/CVE-2022-27404-27405-27406-qtbase-6.2.diff
5.15: https://codereview.qt-project.org/c/qt/tqtc-qtbase/+/423394 or https://download.qt.io/official_releases/qt/5.15/CVE-2022-27404-27405-27406-qtbase-5.15.diff
边栏推荐
- [100 Solidity Skills] 1. Contract reentrancy attack
- Verilog之数码管译码
- SST-Calib: A lidar-visual extrinsic parameter calibration method combining semantics and VO for spatiotemporal synchronization calibration (ITSC 2022)
- 判断一颗树是否为完全二叉树——视频讲解!!!
- 【HMS core】【FAQ】HMS Toolkit典型问题合集1
- spark udf 接受并处理 null值.
- Flink_CDC construction and simple use
- Array of Shell System Learning
- 第1章 Kali与靶机系统
- 阿里云OSS对象存储
猜你喜欢

Security思想项目总结

ospf2 two-point two-way republish (question 2)

Flask's routing (app.route) detailed

Re17:读论文 Challenges for Information Extraction from Dialogue in Criminal Law

(C语言)文件操作

Re15:读论文 LEVEN: A Large-Scale Chinese Legal Event Detection Dataset

JCL learning

图像去噪——Neighbor2Neighbor: Self-Supervised Denoising from Single Noisy Images

Meikle Studio - see the actual combat notes of Hongmeng device development 4 - kernel development

Nacos configuration in the project of battle
随机推荐
flyway的快速入门教程
flowable workflow all business concepts
Basemap和Seaborn
hcip06 ospf special area comprehensive experiment
北京突然宣布,元宇宙重大消息
线上靶机prompt.ml
CVTE校招笔试题+知识点总结
A new generation of free open source terminal tool, so cool
[AGC] Growth Service 2 - In-App Message Example
spark udf 接受并处理 null值.
4. yolov5-6.0 ERROR: AttributeError: 'Upsample' object has no attribute 'recompute_scale_factor' solution
what is this method called
梅科尔工作室-看鸿蒙设备开发实战笔记四——内核开发
阿里云OSS对象存储
Scrapy爬虫之网站图片爬取
nacos实战项目中的配置
Basemap and Seaborn
C语言顺序表基本操作
New in GNOME: Warn users when Secure Boot is disabled
Re16: Read the paper ILDC for CJPE: Indian Legal Documents Corpus for Court Judgment Prediction and Explanation