PT-2008-1527 · Trolltech · Qt

Published

2008-01-08

·

Updated

2011-03-08

·

CVE-2007-5965

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Trolltech Qt versions 4.3.0 through 4.3.2
Description The issue is related to the QSslSocket component in Trolltech Qt, which does not properly verify SSL certificates. This could allow remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.
Recommendations For versions 4.3.0 through 4.3.2, consider updating to a version where the QSslSocket component properly verifies SSL certificates, although the specific fixed version is not provided in the available data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5965

Affected Products

Qt