PT-2013-1191 · Qt Company+4 · Phonon-Backend-Gstreamer+11

Mark Lowe

+1

·

Published

2013-02-06

·

Updated

2021-06-16

·

CVE-2013-0254

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qt versions 4.4.0 through 4.7.5 Qt versions 4.8.x before 4.8.5 Qt version 5.0.0 qt-x11 versions (affected versions not specified) qt-demos-4.6.2 version qt-doc-4.6.2 version qt-examples-4.6.2 version qt-debuginfo-4.6.2 version qt-devel-4.6.2 version phonon-backend-gstreamer-4.6.2 version
Description The vulnerability may lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited remotely. The QSharedMemory class in Qt uses weak permissions for shared memory segments, allowing local users to read sensitive information or modify critical program data.
Recommendations For Qt versions 4.4.0 through 4.7.5, update to a version later than 4.7.5. For Qt versions 4.8.x before 4.8.5, update to version 4.8.5 or later. For Qt version 5.0.0, update to a version later than 5.0.0. For qt-x11, qt-demos-4.6.2, qt-doc-4.6.2, qt-examples-4.6.2, qt-debuginfo-4.6.2, qt-devel-4.6.2, and phonon-backend-gstreamer-4.6.2, update to a version that is not affected by the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability for some of the affected packages.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1566
BDU:2015-07489
BDU:2015-07497
BDU:2015-07499
BDU:2015-07500
BDU:2015-07505
BDU:2015-07506
BDU:2015-07507
BDU:2015-07509
BDU:2015-08951
BDU:2015-08952
BDU:2015-08953
BDU:2015-08954
BDU:2015-08955
BDU:2015-08956
BDU:2015-08957
BDU:2015-09706
CESA-2013_0669
CVE-2013-0254
DLA-210-1
RHSA-2013:0669
RHSA-2013_0669
SUSE-SU-2013_0457-1

Affected Products

Alt Linux
Centos
Qt
Red Hat
Suse
Phonon-Backend-Gstreamer
Qt-Debuginfo
Qt-Demos
Qt-Devel
Qt-Doc
Qt-Examples
Qt-X11