src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade libqt4-sql-x86Upgrade libqt4-sqlUpgrade libqt4-x11-32bitUpgrade libqt4-qt3support-32bitUpgrade libqt4-x86Upgrade libqt4-sql-32bitUpgrade libqt4-qt3support-x86Upgrade libqt4-32bitUpgrade libqt4-x11-x86Upgrade libqt4-x11Upgrade libqt4Upgrade libqt4-sql-sqliteUpgrade libqt4-qt3support | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libqt4-coreUpgrade libqt4-network | Nov 8, 2024 | Sep 2, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub