The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade libqt4-sql-postgresql-x86Upgrade libqt4-x11Upgrade libqt4-develUpgrade libQtWebKit-develUpgrade libqt4-x11-x86Upgrade libQtWebKit4Upgrade libqt4-sql-sqlite-32bitUpgrade libqt4-qt3supportUpgrade libqt4-devel-docUpgrade libqt4-sql-mysql-32bitUpgrade libqt4-sql-sqliteUpgrade libqt4-qt3support-32bitUpgrade libqt4-sql-postgresql-32bitUpgrade libqt4-sql-postgresqlUpgrade libqt4-linguistUpgrade libqt4-sql-unixODBC-32bitUpgrade libqt4-devel-doc-dataUpgrade libqt4-sql-32bitUpgrade libQtWebKit4-x86Upgrade qt4-x11-toolsUpgrade libqt4-sql-unixODBC-x86Upgrade libqt4-qt3support-x86Upgrade libqt4-sqlUpgrade libqt4-sql-x86Upgrade libqt4-32bitUpgrade libqt4-x11-32bitUpgrade libqt4-sql-unixODBCUpgrade libQtWebKit4-32bitUpgrade libqt4Upgrade libqt4-sql-sqlite-x86Upgrade libqt4-sql-mysqlUpgrade libqt4-x86Upgrade libqt4-sql-mysql-x86Upgrade libqt4-private-headers-devel | Dec 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libqt4-coreUpgrade libqt4-network | Nov 8, 2024 | Feb 24, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub