CVE-2012-6093
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an…
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- qt/qt · canonical/ubuntu linux · opensuse/opensuse
- Source
- secalert@redhat.com
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00086.html
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00089.html
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00014.html
- http://lists.qt-project.org/pipermail/announce/2013-January/000020.htmlVendor Advisory
- http://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29
- http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29
- http://secunia.com/advisories/52217Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/01/04/6
- http://www.ubuntu.com/usn/USN-1723-1
- https://bugzilla.redhat.com/show_bug.cgi?id=891955
- https://codereview.qt-project.org/#change%2C42461
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00086.html
- http://lists.opensuse.org/opensuse-updates/2013-01/msg00089.html
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00014.html
- http://lists.qt-project.org/pipermail/announce/2013-January/000020.htmlVendor Advisory
- http://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29
- http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29
- http://secunia.com/advisories/52217Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/01/04/6
- http://www.ubuntu.com/usn/USN-1723-1
- https://bugzilla.redhat.com/show_bug.cgi?id=891955
- https://codereview.qt-project.org/#change%2C42461
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.