Vulnerability Description
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digia | Qt | <= 4.6.3 |
| Qt | Qt | 4.0.0 |
Related Weaknesses (CWE)
References
- http://aluigi.org/adv/qtsslame-adv.txt
- http://aluigi.org/poc/qtsslame.zipExploit
- http://osvdb.org/65860
- http://qt.gitorious.org/qt/qt/commit/c25c7c9bdfade6b906f37ac8bad44f6f0de57597
- http://secunia.com/advisories/40389Vendor Advisory
- http://secunia.com/advisories/46410Vendor Advisory
- http://www.securityfocus.com/bid/41250Exploit
- http://www.vupen.com/english/advisories/2010/1657Vendor Advisory
- https://hermes.opensuse.org/messages/12056605
- http://aluigi.org/adv/qtsslame-adv.txt
- http://aluigi.org/poc/qtsslame.zipExploit
- http://osvdb.org/65860
- http://qt.gitorious.org/qt/qt/commit/c25c7c9bdfade6b906f37ac8bad44f6f0de57597
- http://secunia.com/advisories/40389Vendor Advisory
- http://secunia.com/advisories/46410Vendor Advisory
FAQ
What is CVE-2010-2621?
CVE-2010-2621 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed r...
How severe is CVE-2010-2621?
CVE-2010-2621 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2621?
Check the references section above for vendor advisories and patch information. Affected products include: Digia Qt, Qt Qt.