Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-0254


The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.


Published

2013-02-06T12:05:43.647

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.6 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application qt qt 1.41 Yes
Application qt qt 1.42 Yes
Application qt qt 1.43 Yes
Application qt qt 1.44 Yes
Application qt qt 1.45 Yes
Application qt qt 2.0.0 Yes
Application qt qt 2.0.1 Yes
Application qt qt 2.0.2 Yes
Application qt qt 3.3.0 Yes
Application qt qt 3.3.1 Yes
Application qt qt 3.3.2 Yes
Application qt qt 3.3.3 Yes
Application qt qt 3.3.4 Yes
Application qt qt 3.3.5 Yes
Application qt qt 3.3.6 Yes
Application qt qt 4.0.0 Yes
Application qt qt 4.0.1 Yes
Application qt qt 4.1.0 Yes
Application qt qt 4.1.1 Yes
Application qt qt 4.1.2 Yes
Application qt qt 4.1.3 Yes
Application qt qt 4.1.4 Yes
Application qt qt 4.1.5 Yes
Application qt qt 4.2.0 Yes
Application qt qt 4.2.1 Yes
Application qt qt 4.2.3 Yes
Application qt qt 4.3.0 Yes
Application qt qt 4.3.1 Yes
Application qt qt 4.3.2 Yes
Application qt qt 4.3.3 Yes
Application qt qt 4.3.4 Yes
Application qt qt 4.3.5 Yes
Application qt qt 4.4.0 Yes
Application qt qt 4.4.1 Yes
Application qt qt 4.4.2 Yes
Application qt qt 4.4.3 Yes
Application qt qt 4.5.0 Yes
Application qt qt 4.5.1 Yes
Application qt qt 4.5.2 Yes
Application qt qt 4.5.3 Yes
Application qt qt 4.6.0 Yes
Application qt qt 4.6.1 Yes
Application qt qt 4.6.2 Yes
Application qt qt 4.6.3 Yes
Application qt qt 4.6.4 Yes
Application qt qt 4.6.5 Yes
Application qt qt 4.7.0 Yes
Application qt qt 4.7.1 Yes
Application qt qt 4.7.2 Yes
Application qt qt 4.7.3 Yes
Application qt qt 4.7.4 Yes
Application qt qt 4.7.5 Yes
Application qt qt 4.7.6 Yes
Application qt qt 4.8.0 Yes
Application qt qt 4.8.1 Yes
Application qt qt 4.8.2 Yes
Application qt qt 4.8.3 Yes
Application qt qt 4.8.4 Yes
Application qt qt 4.8.5 Yes
Application qt qt 5.0.0 Yes
Application qt qt 5.0.1 Yes

References