Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
  • Search
  • Get Qt Extensions
  • Unsolved
Collapse
Brand Logo
  1. Home
  2. Qt Development
  3. Installation and Deployment
  4. Qt and OpenSSL Vuluerabilities Impact on Qt Insteller Framework
Forum Update on Monday, May 27th 2025

Qt and OpenSSL Vuluerabilities Impact on Qt Insteller Framework

Scheduled Pinned Locked Moved Unsolved Installation and Deployment
6 Posts 3 Posters 636 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L Offline
    L Offline
    lck2000
    wrote on last edited by
    #1

    One of my Qt Insteller Framework(version 4.1.1)projects found some qt and openssl vulnerabilities in security scans.
    Hopefully someone will tell me if they affect my installation package.
    The followomg are the CVE numbers of these vulnerabilities.
    qt 5.12.7:
    CVE-2020-24742
    CVE-2021-38593
    openssl 1.1.1d:
    CVE-2019-1551
    CVE-2020-1967
    CVE-2020-1971
    CVE-2021-23841
    CVE-2021-23840
    CVE-2021-3449
    CVE-2021-3711
    CVE-2021-3712

    jsulmJ 1 Reply Last reply
    0
    • L lck2000

      One of my Qt Insteller Framework(version 4.1.1)projects found some qt and openssl vulnerabilities in security scans.
      Hopefully someone will tell me if they affect my installation package.
      The followomg are the CVE numbers of these vulnerabilities.
      qt 5.12.7:
      CVE-2020-24742
      CVE-2021-38593
      openssl 1.1.1d:
      CVE-2019-1551
      CVE-2020-1967
      CVE-2020-1971
      CVE-2021-23841
      CVE-2021-23840
      CVE-2021-3449
      CVE-2021-3711
      CVE-2021-3712

      jsulmJ Offline
      jsulmJ Offline
      jsulm
      Lifetime Qt Champion
      wrote on last edited by
      #2

      @lck2000 This is user forum. You should ask on Qt developers mailing list.

      https://forum.qt.io/topic/113070/qt-code-of-conduct

      L 1 Reply Last reply
      0
      • sierdzioS Offline
        sierdzioS Offline
        sierdzio
        Moderators
        wrote on last edited by
        #3

        I think the research bit is on your shoulders here.

        What I can definitely say: upgrade asap! Using old OpenSSL is never a good idea! OpenSSL 1.1.1d is from September 2019.

        And your Qt version is outdated, too. Newest release in 5.12 branch is 5.12.11.

        (Z(:^

        L 1 Reply Last reply
        2
        • jsulmJ jsulm

          @lck2000 This is user forum. You should ask on Qt developers mailing list.

          L Offline
          L Offline
          lck2000
          wrote on last edited by
          #4

          @jsulm Thank you,I will do that

          1 Reply Last reply
          0
          • sierdzioS sierdzio

            I think the research bit is on your shoulders here.

            What I can definitely say: upgrade asap! Using old OpenSSL is never a good idea! OpenSSL 1.1.1d is from September 2019.

            And your Qt version is outdated, too. Newest release in 5.12 branch is 5.12.11.

            L Offline
            L Offline
            lck2000
            wrote on last edited by
            #5

            @sierdzio But the Qt Installer Framework I use relies on these ,and i haven't found a way to update them yet.

            sierdzioS 1 Reply Last reply
            0
            • L lck2000

              @sierdzio But the Qt Installer Framework I use relies on these ,and i haven't found a way to update them yet.

              sierdzioS Offline
              sierdzioS Offline
              sierdzio
              Moderators
              wrote on last edited by
              #6

              @lck2000 said in Qt and OpenSSL Vuluerabilities Impact on Qt Insteller Framework:

              @sierdzio But the Qt Installer Framework I use relies on these ,and i haven't found a way to update them yet.

              You can recompile Qt Installer Framework yourself. It's not a convenient solution, I know.

              (Z(:^

              1 Reply Last reply
              0

              • Login

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • Users
              • Groups
              • Search
              • Get Qt Extensions
              • Unsolved