UBUNTU-CVE-2020-24619

Source
https://ubuntu.com/security/CVE-2020-24619
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-24619.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2020-24619
Related
Published
2020-09-22T12:15:00Z
Modified
2025-01-13T10:22:15Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed download resource.

References

Affected packages

Ubuntu:20.04:LTS / shotcut

Package

Name
shotcut
Purl
pkg:deb/ubuntu/shotcut@20.02.17-2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

19.*

19.12.31-1
19.12.31-2

20.*

20.02.02-1
20.02.17-1
20.02.17-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / shotcut

Package

Name
shotcut
Purl
pkg:deb/ubuntu/shotcut@22.01.30+ds-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

21.*

21.01.29+ds-1
21.10.31+ds-1
21.12.21+ds-1
21.12.24+ds-1

22.*

22.01.30+ds-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / shotcut

Package

Name
shotcut
Purl
pkg:deb/ubuntu/shotcut@24.04.28+ds-1build1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

24.*

24.02.29+ds-1build1
24.04.28+ds-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / shotcut

Package

Name
shotcut
Purl
pkg:deb/ubuntu/shotcut@24.02.29+ds-1build1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

23.*

23.07.29+git20230730+ds-1
23.09+git20231015+ds-1
23.11.29+git20231201+ds-1
23.12.15+git20231218+ds-1

24.*

24.01.28+ds-1
24.01.31+ds-1
24.02.29+ds-1
24.02.29+ds-1build1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}