Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-39936

Опубликовано: 04 июл. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

A vulnerability was found in Qt where, during a TLS connection for servers supporting HTTP2, Qt may send data to a server even if the TLS certificate doesn't match the redirected address. This occurs because Qt fails to validate the certificate against the redirected address, potentially sending data to an incorrect or malicious server.

Отчет

This flaw occurs because Qt does not properly validate the certificate against the redirected address, potentially leading to sensitive data being sent to an unintended or malicious server. Given the potential for significant data exposure, this issue is considered important.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtbaseNot affected
Red Hat Enterprise Linux 7 Extended Lifecycle Supportqt5-qtbaseFixedRHSA-2024:464718.07.2024
Red Hat Enterprise Linux 8qt5-qtbaseFixedRHSA-2024:461718.07.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportqt5-qtbaseFixedRHSA-2024:464619.07.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportqt5-qtbaseFixedRHSA-2024:462118.07.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update Serviceqt5-qtbaseFixedRHSA-2024:462118.07.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionsqt5-qtbaseFixedRHSA-2024:462118.07.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportqt5-qtbaseFixedRHSA-2024:464418.07.2024
Red Hat Enterprise Linux 8.6 Telecommunications Update Serviceqt5-qtbaseFixedRHSA-2024:464418.07.2024
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsqt5-qtbaseFixedRHSA-2024:464418.07.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2295867qtbase: qtbase: Delay any communication until encrypted() can be responded to

EPSS

Процентиль: 38%
0.00167
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 8.6
nvd
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

CVSS3: 5.9
msrc
около 1 года назад

Описание отсутствует

CVSS3: 8.6
debian
около 1 года назад

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2. ...

rocky
около 1 года назад

Important: qt5-qtbase security update

EPSS

Процентиль: 38%
0.00167
Низкий

7.5 High

CVSS3