CVE-2010-2621
EPSS 12.0%Published: 7/2/2010Modified: 6/4/2024
Description
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
Affected packages (1)
- Debian/qt4-x11from 0, < 4:4.6.3-2
References (9)
- ADVISORYhttp://secunia.com/advisories/40389
- ADVISORYhttp://secunia.com/advisories/46410
- ADVISORYhttp://www.vupen.com/english/advisories/2010/1657
- EXPLOIThttp://aluigi.org/poc/qtsslame.zip
- EXPLOIThttp://www.securityfocus.com/bid/41250
- WEBhttp://aluigi.org/adv/qtsslame-adv.txt
- WEBhttp://osvdb.org/65860
- WEBhttp://qt.gitorious.org/qt/qt/commit/c25c7c9bdfade6b906f37ac8bad44f6f0de57597
- WEBhttps://hermes.opensuse.org/messages/12056605