Vulnerability Description
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qt | Qt | 5.0.0 |
Related Weaknesses (CWE)
References
- https://hackinparis.com/data/slides/2017/2017_Cohen_Gil_The_forgotten_interface_Third Party Advisory
- https://www.youtube.com/watch?v=m6zISgWPGGYThird Party Advisory
- https://hackinparis.com/data/slides/2017/2017_Cohen_Gil_The_forgotten_interface_Third Party Advisory
- https://www.youtube.com/watch?v=m6zISgWPGGYThird Party Advisory
FAQ
What is CVE-2017-15011?
CVE-2017-15011 is a vulnerability with a CVSS score of 7.5 (HIGH). The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unsp...
How severe is CVE-2017-15011?
CVE-2017-15011 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15011?
Check the references section above for vendor advisories and patch information. Affected products include: Qt Qt.