PT-2012-1321 · Qt+2 · Qt+2

Thiago Macieira

·

Published

2012-06-19

·

Updated

2021-06-16

·

CVE-2010-5076

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Qt versions prior to 4.7.0-rc1
Description The issue allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. This is possible because QSslSocket in Qt recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate.
Recommendations For Qt versions prior to 4.7.0-rc1, update to version 4.7.0-rc1 or later to resolve the issue. As a temporary workaround, consider restricting the use of QSslSocket until a patch is available. Avoid using QSslSocket with certificates that contain wildcard IP addresses in the Common Name field until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CESA-2012_0880
CVE-2010-5076
RHSA-2012:0880
RHSA-2012_0880

Affected Products

Centos
Qt
Red Hat