← Back

CVE-2012-6093

nvd nist
Published: Feb 24, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.

Affected (25)

1 product
Qt
1 product
Ubuntu Linux
1 product
Opensuse
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Qt
Up to 4.6.5
Version 4.6.0
Version 4.6.0 rc1
Version 4.6.1
Version 4.6.2
Version 4.6.3
Version 4.6.4
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Qt
Version 4.7.0
Version 4.7.1
Version 4.7.2
Version 4.7.3
Version 4.7.4
Version 4.7.5
Version 4.7.6 rc
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Qt
Version 4.8.0
Version 4.8.1
Version 4.8.2
Version 4.8.3
Version 4.8.4
Configuration D
6 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 10.04
Version 11.10
Version 12.04
Version 12.10
Opensuse
Version 11.4
Version 12.2

Related CWEs

References (24)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.