Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-6093
Description:The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an incorrect error when certificate validation fails and might cause users to make unsafe security decisions to accept a certificate.
Test IDs: 1.3.6.1.4.1.25623.1.0.865223   1.3.6.1.4.1.25623.1.0.864991  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-6093
52217
http://secunia.com/advisories/52217
USN-1723-1
http://www.ubuntu.com/usn/USN-1723-1
[Announce] 20130102 Qt Project Security Advisory: QSslSocket may report incorrect errors when certificate verification fails
http://lists.qt-project.org/pipermail/announce/2013-January/000020.html
[oss-security] 20130104 Re: CVE Request -- qt: QSslSocket might report inappropriate errors when certificate verification fails
http://www.openwall.com/lists/oss-security/2013/01/04/6
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697582
http://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29
http://qt.gitorious.org/qt/qt/commit/3b14dc93cf0ef06f1424d7d6319a1af4505faa53%20%284.7%29
http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29
http://qt.gitorious.org/qt/qt/commit/691e78e5061d4cbc0de212d23b06c5dffddf2098%20%284.8%29
https://bugzilla.redhat.com/show_bug.cgi?id=891955
https://bugzilla.redhat.com/show_bug.cgi?id=891955
https://codereview.qt-project.org/#change%2C42461
https://codereview.qt-project.org/#change%2C42461
openSUSE-SU-2013:0204
http://lists.opensuse.org/opensuse-updates/2013-01/msg00086.html
openSUSE-SU-2013:0211
http://lists.opensuse.org/opensuse-updates/2013-01/msg00089.html
openSUSE-SU-2013:0256
http://lists.opensuse.org/opensuse-updates/2013-02/msg00014.html




© 1998-2025 E-Soft Inc. All rights reserved.