PT-2008-1527 · Trolltech · Qt
Published
2008-01-08
·
Updated
2011-03-08
·
CVE-2007-5965
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Trolltech Qt versions 4.3.0 through 4.3.2
Description
The issue is related to the QSslSocket component in Trolltech Qt, which does not properly verify SSL certificates. This could allow remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.
Recommendations
For versions 4.3.0 through 4.3.2, consider updating to a version where the QSslSocket component properly verifies SSL certificates, although the specific fixed version is not provided in the available data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qt