4.3

CVE-2012-6093

The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QtQt Updaterc Version <= 4.6.5
QtQt Version4.6.0
QtQt Version4.6.0 Updaterc1
QtQt Version4.6.1
QtQt Version4.6.2
QtQt Version4.6.3
QtQt Version4.6.4
QtQt Version4.7.0
QtQt Version4.7.1
QtQt Version4.7.2
QtQt Version4.7.3
QtQt Version4.7.4
QtQt Version4.7.5
QtQt Version4.7.6 Updaterc
QtQt Version4.8.0
QtQt Version4.8.1
QtQt Version4.8.2
QtQt Version4.8.3
QtQt Version4.8.4
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
OpensuseOpensuse Version11.4
OpensuseOpensuse Version12.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.28% 0.841
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N