Predictable PRNG seeding in QAbstractOAuth (CVE-2024-36048) #shorts #breaking

CVE

This CVE, identified as CVE-2024-36048, highlights a significant security vulnerability in the Qt framework's network authorization component. Specifically, the vulnerability arises due to predictable random number generation in QAbstractOAuth. This vulnerability can be found in versions of Qt Network Authorization prior to 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1. Due to this flaw, attackers can predict random values, potentially compromising security mechanisms dependent on randomness. The vulnerability was last updated 5 months ago. While it's not a zero-day exploit and no specific attacks have been reported, developers and users of affected Qt versions should be aware of this issue due to the inherent risks associated with predictable random values.

Watch the full video on YouTube: CVE-2024-36048

Remediation and exploitation details

This chain involves the following actors

This following systems are involved

Attack entry point

Remediation actions

Exploitation actions

Related Content

NOTE: The following related content has not been vetted and may be unsafe.

CVE database technical details

CVE ID
CVE-2024-36048
Description
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Provider
mitre
CWE / problem types
n/a
Affected Software Versions
n/a:n/a:[{'version': 'n/a', 'status': 'affected'}]
Date Published
2024-05-18T00:00:00
Last Updated
2024-08-08T14:36:16.452Z