Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0254

Опубликовано: 05 фев. 2013
Источник: redhat
CVSS2: 4.4
EPSS Низкий

Описание

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5qtNot affected
Red Hat Enterprise Linux 6qt3Not affected
Red Hat Enterprise Linux 6qtFixedRHSA-2013:066921.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=907425qt: QSharedMemory class created shared memory segments with insecure permissions

EPSS

Процентиль: 25%
0.00082
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

nvd
больше 12 лет назад

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

debian
больше 12 лет назад

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before ...

github
больше 3 лет назад

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

oracle-oval
больше 12 лет назад

ELSA-2013-0669: qt security update (MODERATE)

EPSS

Процентиль: 25%
0.00082
Низкий

4.4 Medium

CVSS2