QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade qt-examplesUpgrade qt-postgresqlUpgrade qt-demosUpgrade phonon-backend-gstreamerUpgrade qt-develUpgrade qt-x11Upgrade qt-mysqlUpgrade qt-sqliteUpgrade qtUpgrade qt-odbcUpgrade qt-doc | Dec 1, 2016 | Jun 29, 2012 |
| Oracle_linux | — | Upgrade qt-mysqlUpgrade qt-postgresqlUpgrade qtUpgrade qt-demosUpgrade qt-sqliteUpgrade qt-x11Upgrade qt-docUpgrade qt-odbcUpgrade qt-develUpgrade qt-examplesUpgrade phonon-backend-gstreamer | Oct 16, 2024 | Jun 29, 2012 |
| Ubuntu | — | Upgrade libqtgui4Upgrade libqt4-network | Nov 8, 2024 | Jun 29, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub