Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3q6-g74w-mvvq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

EPSS

Процентиль: 65%
0.00495
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

redhat
больше 15 лет назад

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

nvd
больше 13 лет назад

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

debian
больше 13 лет назад

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in ...

oracle-oval
больше 13 лет назад

ELSA-2012-0880: qt security and bug fix update (MODERATE)

EPSS

Процентиль: 65%
0.00495
Низкий

Дефекты

CWE-20