Bug 411751 (CVE-2007-5965) - CVE-2007-5965 qt4: QSslSocket may skip SSL certificate verification
Summary: CVE-2007-5965 qt4: QSslSocket may skip SSL certificate verification
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-5965
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 427232 427233
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-12-05 10:01 UTC by Tomas Hoger
Modified: 2021-11-12 19:46 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2008-01-02 08:18:15 UTC
Embargoed:


Attachments (Terms of Use)
Upstream patch (1.51 KB, patch)
2007-12-05 10:03 UTC, Tomas Hoger
no flags Details | Diff

Description Tomas Hoger 2007-12-05 10:01:25 UTC
Thiago José Macieira of Trolltech informed us of following problem affecting QT4
library:

Qt 4 has a potential vulnerability in QSslSocket, which might cause a
certificate verification in SSL connections not to be performed. As a 
consequence, code using QSslSocket might be mislead into thinking the 
certificate was verified correctly when it actually failed in one or more 
criteria.

Versions affected: 4.3.0, 4.3.1 and 4.3.2

Comment 1 Tomas Hoger 2007-12-05 10:03:17 UTC
Created attachment 277991 [details]
Upstream patch

Comment 2 Tomas Hoger 2007-12-05 10:09:31 UTC
This issue did not affect versions of qt and qt4 packages as shipped with Red
Hat Enterprise Linux 2.1, 3, 4, or 5.

Packages shipped are in version < 4.3 and do not contain vulnerable code.


Comment 5 Tomas Hoger 2008-01-02 08:07:50 UTC
Fedora updates already built and available via testing repository:

https://admin.fedoraproject.org/updates/F7/FEDORA-2007-4354
https://admin.fedoraproject.org/updates/F8/FEDORA-2007-4285



Note You need to log in before you can comment on or make changes to this bug.