The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x...
Vulnerability Description
The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-0254
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00015.html
- http://rhn.redhat.com/errata/RHSA-2013-0669.html
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00014.html
- http://lists.qt-project.org/pipermail/announce/2013-February/000023.html
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00019.html
- https://bugzilla.redhat.com/show_bug.cgi?id=907425
More from qt
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.