Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Get Qt Extensions
  • Unsolved
Collapse
Brand Logo
  1. Home
  2. Qt Development
  3. General and Desktop
  4. Qt and CVSS score for security flaws.
Forum Updated to NodeBB v4.3 + New Features

Qt and CVSS score for security flaws.

Scheduled Pinned Locked Moved Unsolved General and Desktop
3 Posts 3 Posters 342 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D Offline
    D Offline
    DeepakH
    wrote on last edited by
    #1

    Hello everyone,

    I recently got a chance to test my windows application built in Qt5.12.3 for vulnerabilities using Blackduck tool ( by Synopsis ).
    A quick scan of my binaries gave me a list of known vulnerabilities - having high CVSS score - in a few Qt libaries and its dependent libraries.
    Any idea on how Qt manages its security issues?
    Does Qt follow any mechanism for fixing its security related issues or is there any forum where I can know how to fix these security issues ?

    Any information on this would be greatly helpful!

    JKSHJ 1 Reply Last reply
    0
    • D DeepakH

      Hello everyone,

      I recently got a chance to test my windows application built in Qt5.12.3 for vulnerabilities using Blackduck tool ( by Synopsis ).
      A quick scan of my binaries gave me a list of known vulnerabilities - having high CVSS score - in a few Qt libaries and its dependent libraries.
      Any idea on how Qt manages its security issues?
      Does Qt follow any mechanism for fixing its security related issues or is there any forum where I can know how to fix these security issues ?

      Any information on this would be greatly helpful!

      JKSHJ Offline
      JKSHJ Offline
      JKSH
      Moderators
      wrote on last edited by
      #2

      @DeepakH said in Qt and CVSS score for security flaws.:

      I recently got a chance to test my windows application built in Qt5.12.3 for vulnerabilities

      Qt 5.12.3 is almost 2 years old.

      Please re-run your tests against Qt 5.12.10, which includes security fixes and bug fixes for Qt versions 5.12.3 to 5.12.9.

      Any idea on how Qt manages its security issues?
      Does Qt follow any mechanism for fixing its security related issues or is there any forum where I can know how to fix these security issues ?

      Here is the official security policy of the Qt Project: http://quips-qt-io.herokuapp.com/quip-0015-Security-Policy.html

      Qt Doc Search for browsers: forum.qt.io/topic/35616/web-browser-extension-for-improved-doc-searches

      1 Reply Last reply
      1
      • SGaistS Offline
        SGaistS Offline
        SGaist
        Lifetime Qt Champion
        wrote on last edited by
        #3

        Hi and welcome to devnet,

        You have the details of their handling in QUIP15

        Interested in AI ? www.idiap.ch
        Please read the Qt Code of Conduct - https://forum.qt.io/topic/113070/qt-code-of-conduct

        1 Reply Last reply
        2

        • Login

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Users
        • Groups
        • Search
        • Get Qt Extensions
        • Unsolved