The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 29, 2010 |
| Suse | — | Upgrade libqt4-sql-32bitUpgrade libQtWebKit4-32bitUpgrade qt4-x11-toolsUpgrade libqt4-x11-32bitUpgrade libqt4-sqlUpgrade libqt4-32bitUpgrade libqt4-sql-postgresql-32bitUpgrade libqt4-sql-mysqlUpgrade libqt4-sql-sqlite-32bitUpgrade libqt4-qt3support-x86Upgrade libqt4-qt3supportUpgrade libqt4Upgrade libqt4-x11Upgrade libqt4-sql-sqliteUpgrade libqt4-sql-postgresqlUpgrade libQtWebKit4Upgrade libqt4-sql-mysql-32bitUpgrade libqt4-sql-unixODBCUpgrade libqt4-x86Upgrade libQtWebKit4-x86Upgrade libqt4-x11-x86Upgrade libqt4-sql-x86Upgrade libqt4-qt3support-32bitUpgrade qt4-qtscriptUpgrade libqt4-sql-unixODBC-32bit | Dec 12, 2013 | Jul 2, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub