Vulnerability Name: | CVE-2010-2621 (CCN-59833) | ||||||||
Assigned: | 2010-06-29 | ||||||||
Published: | 2010-06-29 | ||||||||
Updated: | 2021-06-16 | ||||||||
Summary: | The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: CCN Type: Luigi Auriemma Advisory, 29 Jun 2010 Endless loop in Qt QSSLsocket 4.6.3 Source: MISC Type: UNKNOWN http://aluigi.org/adv/qtsslame-adv.txt Source: MISC Type: Exploit http://aluigi.org/poc/qtsslame.zip Source: MITRE Type: CNA CVE-2010-2621 Source: OSVDB Type: UNKNOWN 65860 Source: CONFIRM Type: UNKNOWN http://qt.gitorious.org/qt/qt/commit/c25c7c9bdfade6b906f37ac8bad44f6f0de57597 Source: CCN Type: Qt Web site Qt Source: CCN Type: SA40389 Qt QSslSocketBackendPrivate::transmit() Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 40389 Source: CCN Type: SA40739 CometBird Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 46410 Source: CCN Type: CometBird Web site Download - CometBird - a lightweight, powerful and fast web browser Source: CCN Type: Comet Forums CometBird version 3.6.7 has been released Source: CCN Type: OSVDB ID: 65860 Qt src/network/ssl/qsslsocket_openssl.cpp QSslSocketBackendPrivate::transmit() Function DoS Source: BID Type: Exploit 41250 Source: CCN Type: BID-41250 Qt Remote Denial of Service Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2010-1657 Source: XF Type: UNKNOWN qt-qsslsocketbackendprivate-dos(59833) Source: SUSE Type: UNKNOWN SUSE-SU-2011:1113 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [07-08-2010] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |