Assigner | mitre |
Reserved | 2024-05-18 |
Published | 2024-05-18 |
Updated | 2024-06-10 |
Description
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
References
https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317
https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGB6KUPJFQWUBKXVDPJUMAD6KNJJEWPW/ (FEDORA-2024-3936682805)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPHAI3DKDCIU6XLNS6PV6GFS2PHH3GZM/ (FEDORA-2024-bfb8617ba3)
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZOOZZZSK5PNRHFGQMUGUHVYWLILFJCRS/ (FEDORA-2024-2e27372d4c)