The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade qt4-x11-toolsUpgrade libqt4-x11Upgrade libqt4-sqlUpgrade libqt4-sql-sqliteUpgrade libqt4Upgrade libqt4-private-headers-develUpgrade libqt4-debugsourceUpgrade libqt4-qt3support-debuginfo-x86Upgrade libqt4-sql-mysql-32bitUpgrade libqt4-x86Upgrade libqt4-x11-debuginfoUpgrade libqt4-devel-doc-dataUpgrade libqt4-32bitUpgrade libqt4-sql-sqlite-32bitUpgrade libqt4-sql-mysqlUpgrade libqt4-sql-debuginfoUpgrade libqt4-devel-debuginfoUpgrade libqt4-sql-sqlite-debuginfo-32bitUpgrade libqt4-develUpgrade libqt4-sql-32bitUpgrade libqt4-sql-postgresqlUpgrade libqt4-x11-debuginfo-x86Upgrade libqt4-debuginfo-x86Upgrade libqt4-sql-debuginfo-x86Upgrade libqt4-sql-unixODBC-32bitUpgrade libqt4-qt3support-32bitUpgrade libqt4-sql-unixODBCUpgrade libqt4-debuginfo-32bitUpgrade libqt4-devel-docUpgrade libqt4-qt3support-x86Upgrade libqt4-sql-pluginsUpgrade libqt4-debuginfoUpgrade libqt4-sql-sqlite-debuginfo-x86Upgrade libqt4-x11-x86Upgrade libqt4-x11-debuginfo-32bitUpgrade libqt4-sql-debuginfo-32bitUpgrade libqt4-qt3support-debuginfo-32bitUpgrade libqt4-sql-sqlite-x86Upgrade libqt4-qt3supportUpgrade libqt4-sql-x86Upgrade libqt4-qt3support-debuginfoUpgrade libqt4-sql-postgresql-32bitUpgrade libqt4-x11-32bitUpgrade libqt4-sql-sqlite-debuginfo | Dec 12, 2013 | Feb 24, 2013 |
| Ubuntu | — | Upgrade libqt4-coreUpgrade libqt4-network | Nov 8, 2024 | Feb 24, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub