4.3
CVE-2012-6093
- EPSS 1.78%
- Veröffentlicht 24.02.2013 19:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 10.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.78% | 0.753 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
http://secunia.com/advisories/52217
http://www.ubuntu.com/usn/USN-1723-1
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582
http://lists.opensuse.org/opensuse-updates/2013-01/msg00086.html
http://lists.opensuse.org/opensuse-updates/2013-01/msg00089.html
http://lists.opensuse.org/opensuse-updates/2013-02/msg00014.html
http://lists.qt-project.org/pipermail/announce/2013-January/000020.html
http://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29
http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29
http://www.openwall.com/lists/oss-security/2013/01/04/6
https://bugzilla.redhat.com/show_bug.cgi?id=891955
https://codereview.qt-project.org/#change%2C42461