5
CVSSv2

CVE-2010-2621

Published: 02/07/2010 Updated: 16/06/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and previous versions allows remote malicious users to cause a denial of service (infinite loop) via a malformed request.

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt 4.6.0

qt qt 4.5.2

qt qt 4.5.3

qt qt 4.5.0

qt qt 4.2.0

qt qt 4.1.5

qt qt 4.1.0

qt qt 4.1.4

digia qt

qt qt 4.6.1

qt qt 4.4.0

qt qt 4.4.2

qt qt 4.3.5

qt qt 4.2.1

qt qt 4.1.3

qt qt 4.1.1

qt qt 4.3.3

qt qt 4.3.2

qt qt 4.3.1

qt qt 4.3.0

qt qt 4.0.0

qt qt 4.6.2

qt qt 4.5.1

qt qt 4.4.1

qt qt 4.4.3

qt qt 4.3.4

qt qt 4.2.3

qt qt 4.1.2

qt qt 4.0.1

Vendor Advisories

Debian Bug report logs - #587711 libqt4-network: infinite loop in QSslSocketBackendPrivate::transmit() Package: libqt4-network; Maintainer for libqt4-network is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Source for libqt4-network is src:qt4-x11 (PTS, buildd, popcon) Reported by: Raphael Geissert <geissert ...

Exploits

Source: aluigiorg/adv/qtsslame-advtxt ####################################################################### Luigi Auriemma Application: Qt qtnokiacom Versions: <= 463 Platforms: Windows, Mac OS X, Linux, mobile devices Bug: QSSLsocket endless loop Exploitation: remote, versus server Date: 29 Jun 2010 Author: Luigi Auriem ...