4.3

CVE-2012-6093

The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.

Data is provided by the National Vulnerability Database (NVD)
QtQt Updaterc Version <= 4.6.5
QtQt Version4.6.0
QtQt Version4.6.0 Updaterc1
QtQt Version4.6.1
QtQt Version4.6.2
QtQt Version4.6.3
QtQt Version4.6.4
QtQt Version4.7.0
QtQt Version4.7.1
QtQt Version4.7.2
QtQt Version4.7.3
QtQt Version4.7.4
QtQt Version4.7.5
QtQt Version4.7.6 Updaterc
QtQt Version4.8.0
QtQt Version4.8.1
QtQt Version4.8.2
QtQt Version4.8.3
QtQt Version4.8.4
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
OpensuseOpensuse Version11.4
OpensuseOpensuse Version12.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.1% 0.759
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N