Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-6093


The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.


Published

2013-02-24T19:55:00.907

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qt qt ≤ 4.6.5 Yes
Application qt qt 4.6.0 Yes
Application qt qt 4.6.0 Yes
Application qt qt 4.6.1 Yes
Application qt qt 4.6.2 Yes
Application qt qt 4.6.3 Yes
Application qt qt 4.6.4 Yes
Application qt qt 4.7.0 Yes
Application qt qt 4.7.1 Yes
Application qt qt 4.7.2 Yes
Application qt qt 4.7.3 Yes
Application qt qt 4.7.4 Yes
Application qt qt 4.7.5 Yes
Application qt qt 4.7.6 Yes
Application qt qt 4.8.0 Yes
Application qt qt 4.8.1 Yes
Application qt qt 4.8.2 Yes
Application qt qt 4.8.3 Yes
Application qt qt 4.8.4 Yes
Operating System canonical ubuntu_linux 10.04 Yes
Operating System canonical ubuntu_linux 11.10 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System canonical ubuntu_linux 12.10 Yes
Operating System opensuse opensuse 11.4 Yes
Operating System opensuse opensuse 12.2 Yes

References