vulnerability

FreeBSD: VID-f5fa174d-19de-11ef-83d8-4ccc6adda413 (CVE-2024-36048): QtNetworkAuth -- predictable seeding of PRNG in QAbstractOAuth

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
May 24, 2024
Added
May 25, 2024
Modified
Dec 10, 2025

Description

Andy Shaw reports: The OAuth1 implementation in QtNetworkAuth created nonces using a PRNG that was seeded with a predictable seed. This means that an attacker that can somehow control the time of the first OAuth1 flow of the process has a high chance of predicting the nonce used in said OAuth flow.

Solutions

freebsd-upgrade-package-qt5-networkauthfreebsd-upgrade-package-qt6-networkauth
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.