CVE-2012-6093
published 2013-02-24CVE-2012-6093: The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.78%
76.0th percentile
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qt | qt | <= 4.6.5 | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Qt vulnerabilities
vendor_ubuntu·2013-02-14·CVSS 4.3
CVE-2012-5624 [MEDIUM] Qt vulnerabilities
Title: Qt vulnerabilities
Summary: Several security issues were fixed in Qt.
Richard J. Moore and Peter Hartmann discovered that Qt allowed redirecting
requests from http to file schemes. If an attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to view sensitive
information. This issue only affected Ubuntu 11.10, Ubuntu 12.04 LTS,
and Ubuntu 12.10. (CVE-2012-5624)
Stephen Cheng discovered that Qt may report incorrect errors when ssl
certificate verification fails. (CVE-2012-6093)
Tim Brown and Mark Lowe discovered that Qt incorrectly used weak
permissions on shared memory segments. A local attacker could use this
issue to view sensitive information, or modify program data belonging to
other users. (CVE-2013-0254)
Instructions: After a standard s
Red Hat
qt: QSslSocket might report inappropriate errors when certificate verification fails
vendor_redhat·2013-01-02·CVSS 4.3
CVE-2012-6093 [MEDIUM] qt: QSslSocket might report inappropriate errors when certificate verification fails
qt: QSslSocket might report inappropriate errors when certificate verification fails
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
Statement: Not vulnerable. This issue did not affect the versions of Qt as shipped with Red Hat Enterprise Linux 5 and 6.
Package: qt (Red Hat Enterprise Linux 5) - Not affected
Package: qt4 (Red Hat Enterprise Linux 5) - Not affected
Package: qt (Red Hat Enterprise Linux 6) - Not affected
Package: qt3 (Red Hat Enterprise Linu
GHSA
GHSA-8vmr-c9ff-vrfh: The QSslSocket::sslErrors function in Qt before 4
ghsa_unreviewed·2022-05-13
CVE-2012-6093 [MEDIUM] GHSA-8vmr-c9ff-vrfh: The QSslSocket::sslErrors function in Qt before 4
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582http://lists.opensuse.org/opensuse-updates/2013-01/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00089.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00014.htmlhttp://lists.qt-project.org/pipermail/announce/2013-January/000020.htmlhttp://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29http://secunia.com/advisories/52217http://www.openwall.com/lists/oss-security/2013/01/04/6http://www.ubuntu.com/usn/USN-1723-1https://bugzilla.redhat.com/show_bug.cgi?id=891955https://codereview.qt-project.org/#change%2C42461http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582http://lists.opensuse.org/opensuse-updates/2013-01/msg00086.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00089.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00014.htmlhttp://lists.qt-project.org/pipermail/announce/2013-January/000020.htmlhttp://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29http://secunia.com/advisories/52217http://www.openwall.com/lists/oss-security/2013/01/04/6http://www.ubuntu.com/usn/USN-1723-1https://bugzilla.redhat.com/show_bug.cgi?id=891955https://codereview.qt-project.org/#change%2C42461
2013-02-24
Published