Bug 411751 - (CVE-2007-5965) CVE-2007-5965 qt4: QSslSocket may skip SSL certificate verification
CVE-2007-5965 qt4: QSslSocket may skip SSL certificate verification
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 427232 427233
  Show dependency treegraph
Reported: 2007-12-05 05:01 EST by Tomas Hoger
Modified: 2008-01-02 08:07 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-01-02 03:18:15 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Upstream patch (1.51 KB, patch)
2007-12-05 05:03 EST, Tomas Hoger
no flags Details | Diff

  None (edit)
Description Tomas Hoger 2007-12-05 05:01:25 EST
Thiago José Macieira of Trolltech informed us of following problem affecting QT4

Qt 4 has a potential vulnerability in QSslSocket, which might cause a
certificate verification in SSL connections not to be performed. As a 
consequence, code using QSslSocket might be mislead into thinking the 
certificate was verified correctly when it actually failed in one or more 

Versions affected: 4.3.0, 4.3.1 and 4.3.2
Comment 1 Tomas Hoger 2007-12-05 05:03:17 EST
Created attachment 277991 [details]
Upstream patch
Comment 2 Tomas Hoger 2007-12-05 05:09:31 EST
This issue did not affect versions of qt and qt4 packages as shipped with Red
Hat Enterprise Linux 2.1, 3, 4, or 5.

Packages shipped are in version < 4.3 and do not contain vulnerable code.
Comment 5 Tomas Hoger 2008-01-02 03:07:50 EST
Fedora updates already built and available via testing repository:


Note You need to log in before you can comment on or make changes to this bug.