3.6
CVSSv2

CVE-2013-0254

Published: 06/02/2013 Updated: 16/06/2021
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The QSharedMemory class in Qt 5.0.0, 4.8.x prior to 4.8.5, 4.7.x prior to 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qt qt 1.41

qt qt 1.44

qt qt 1.45

qt qt 1.42

qt qt 1.43

qt qt 2.0.0

qt qt 2.0.1

qt qt 2.0.2

qt qt 3.3.4

qt qt 3.3.5

qt qt 3.3.6

qt qt 3.3.2

qt qt 3.3.3

qt qt 3.3.0

qt qt 3.3.1

qt qt 4.1.2

qt qt 4.1.3

qt qt 4.1.4

qt qt 4.1.5

qt qt 4.1.0

qt qt 4.1.1

qt qt 4.0.0

qt qt 4.0.1

qt qt 4.2.1

qt qt 4.2.3

qt qt 4.2.0

qt qt 4.3.0

qt qt 4.3.1

qt qt 4.3.2

qt qt 4.3.3

qt qt 4.3.4

qt qt 4.3.5

qt qt 4.4.1

qt qt 4.4.2

qt qt 4.4.3

qt qt 4.4.0

qt qt 4.5.2

qt qt 4.5.3

qt qt 4.5.0

qt qt 4.5.1

qt qt 4.6.0

qt qt 4.6.1

qt qt 4.6.2

qt qt 4.6.5

qt qt 4.6.3

qt qt 4.6.4

qt qt 4.7.1

qt qt 4.7.2

qt qt 4.7.3

qt qt 4.7.4

qt qt 4.7.0

qt qt 4.7.5

qt qt 4.7.6

qt qt 4.8.1

qt qt 4.8.2

qt qt 4.8.3

qt qt 4.8.4

qt qt 4.8.0

qt qt 4.8.5

qt qt 5.0.0

qt qt 5.0.1

Vendor Advisories

Synopsis Moderate: qt security update Type/Severity Security Advisory: Moderate Topic Updated qt packages that fix one security issue are now available forRed Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact A Common Vulnerability Scoring Sys ...
Debian Bug report logs - #699870 [CVE-2013-0254] Qt Project Security Advisory: System V shared memory segments created world-writeable Package: qt4-x11; Maintainer for qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 6 Feb 2013 02:21:02 ...
Several security issues were fixed in Qt ...