Red Hat Bugzilla – Bug 427232
CVE-2007-5965 qt4: QSslSocket may skip SSL certificate verification
Last modified: 2008-01-02 20:45:35 EST
+++ This bug was initially created as a clone of Bug #411751 +++
Thiago José Macieira of Trolltech informed us of following problem affecting QT4
Qt 4 has a potential vulnerability in QSslSocket, which might cause a
certificate verification in SSL connections not to be performed. As a
consequence, code using QSslSocket might be mislead into thinking the
certificate was verified correctly when it actually failed in one or more
Versions affected: 4.3.0, 4.3.1 and 4.3.2
-- Additional comment from email@example.com on 2007-12-05 05:03 EST --
Created an attachment (id=277991)
-- Additional comment from firstname.lastname@example.org on 2007-12-05 05:09 EST --
This issue did not affect versions of qt and qt4 packages as shipped with Red
Hat Enterprise Linux 2.1, 3, 4, or 5.
Packages shipped are in version < 4.3 and do not contain vulnerable code.
-- Additional comment from email@example.com on 2008-01-02 03:06 EST --
-- Additional comment from firstname.lastname@example.org on 2008-01-02 03:07 EST --
Fedora updates already built and available via testing repository:
qt4-4.3.3-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.