MEDIUM
(QSslSocketBackendPrivate): DoS (infinite loop) via malformed request
Published Jul 2, 2010
5.0
MEDIUMCVSS 2.0
EPSS 10.54%
Description
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
Affected products
No data.
OR
- ≤ 4.6.3
- 4.0.0
- 4.0.1
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.5
- 4.2.0
- 4.2.1
- 4.2.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.3
- 4.5.0
- 4.5.1
- 4.5.2
- 4.5.3
- 4.6.0
- 4.6.0
- 4.6.1
- 4.6.2
No data.
Red Hat Enterprise Linux 6
qt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | qt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Weaknesses (2)
References (13)
- http://aluigi.org/adv/qtsslame-adv.txt x_refsource_MISC
- http://aluigi.org/poc/qtsslame.zip x_refsource_MISCExploit
- http://osvdb.org/65860 vdb-entryx_refsource_OSVDB
- http://qt.gitorious.org/qt/qt/commit/c25c7c9bdfade6b906f37ac8bad44f6f0de57597 x_refsource_CONFIRM
- http://secunia.com/advisories/40389 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/46410 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/41250 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2010/1657 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-2621 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=611086 Issue Tracking
- https://hermes.opensuse.org/messages/12056605 vendor-advisoryx_refsource_SUSE
- https://nvd.nist.gov/vuln/detail/CVE-2010-2621
- https://www.cve.org/CVERecord?id=CVE-2010-2621
| Link | Providers | Tags |
|---|---|---|
| http://aluigi.org/adv/qtsslame-adv.txt | x_refsource_MISC | |
| http://aluigi.org/poc/qtsslame.zip | x_refsource_MISCExploit | |
| http://osvdb.org/65860 | vdb-entryx_refsource_OSVDB | |
| http://qt.gitorious.org/qt/qt/commit/c25c7c9bdfade6b906f37ac8bad44f6f0de57597 | x_refsource_CONFIRM | |
| http://secunia.com/advisories/40389 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/46410 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/41250 | vdb-entryx_refsource_BIDExploit | |
| http://www.vupen.com/english/advisories/2010/1657 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2010-2621 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=611086 | Issue Tracking | |
| https://hermes.opensuse.org/messages/12056605 | vendor-advisoryx_refsource_SUSE | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-2621 | ||
| https://www.cve.org/CVERecord?id=CVE-2010-2621 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 2, 2010
Updated Aug 7, 2024
Reserved Jul 2, 2010
Link CVE-2010-2621
CISA Vulnrichment
Updated n/a