PT-2008-1527 · Trolltech · Qt
Publicado
2008-01-08
·
Atualizado
2011-03-08
·
CVE-2007-5965
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Trolltech Qt versions 4.3.0 through 4.3.2
Description
The issue is related to the QSslSocket component in Trolltech Qt, which does not properly verify SSL certificates. This could allow remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.
Recommendations
For versions 4.3.0 through 4.3.2, consider updating to a version where the QSslSocket component properly verifies SSL certificates, although the specific fixed version is not provided in the available data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qt