QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade qt-develUpgrade qt-x11Upgrade qt-mysqlUpgrade phonon-backend-gstreamerUpgrade qt-demosUpgrade qt-postgresqlUpgrade qt-examplesUpgrade qtUpgrade qt-sqliteUpgrade qt-odbcUpgrade qt-doc | Dec 1, 2016 | Jun 29, 2012 |
| Oracle_linux | — | Upgrade qt-develUpgrade phonon-backend-gstreamerUpgrade qt-examplesUpgrade qt-odbcUpgrade qt-sqliteUpgrade qt-postgresqlUpgrade qt-x11Upgrade qtUpgrade qt-docUpgrade qt-mysqlUpgrade qt-demos | Oct 16, 2024 | Jun 29, 2012 |
| Ubuntu | — | Upgrade libqt4-networkUpgrade libqtgui4 | Nov 8, 2024 | Jun 29, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub