4.3
CVSSv2

CVE-2012-5624

Published: 24/02/2013 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The XMLHttpRequest object in Qt prior to 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle malicious users to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt 4.2.3

digia qt

qt qt 1.41

qt qt 1.44

qt qt 1.45

qt qt 1.42

qt qt 1.43

qt qt 2.0.0

qt qt 3.3.0

qt qt 2.0.1

qt qt 2.0.2

qt qt 3.3.3

qt qt 3.3.4

qt qt 3.3.1

qt qt 3.3.2

qt qt 4.0.1

qt qt 4.1.0

qt qt 3.3.5

qt qt 3.3.6

qt qt 4.1.3

qt qt 4.1.4

qt qt 4.1.1

qt qt 4.1.2

qt qt 4.2.1

qt qt 4.1.5

qt qt 4.3.2

qt qt 4.3.3

qt qt 4.3.0

qt qt 4.3.1

qt qt 4.4.0

qt qt 4.4.1

qt qt 4.3.4

qt qt 4.3.5

qt qt 4.5.0

qt qt 4.5.1

qt qt 4.4.2

qt qt 4.4.3

qt qt 4.6.0

qt qt 4.5.2

qt qt 4.5.3

qt qt 4.6.3

qt qt 4.6.4

qt qt 4.6.1

qt qt 4.6.2

qt qt 4.7.2

qt qt 4.7.3

qt qt 4.7.0

qt qt 4.7.1

qt qt 4.2.0

qt qt 4.7.5

qt qt 4.7.4

qt qt 4.0.0

qt qt 4.8.2

qt qt 4.6.5

qt qt 4.7.6

qt qt 4.8.0

qt qt 4.8.1

canonical ubuntu linux 11.10

canonical ubuntu linux 12.10

canonical ubuntu linux 12.04

canonical ubuntu linux 10.04

Vendor Advisories

Debian Bug report logs - #695156 Qt QML XmlHttpRequest insecure redirection Package: qt4-x11; Maintainer for qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Tue, 4 Dec 2012 18:06:02 UTC Severity: serious Tags: patch, security Fixed in ve ...
Several security issues were fixed in Qt ...