Lucene search

K
cve[email protected]CVE-2010-2621
HistoryJul 02, 2010 - 8:30 p.m.

CVE-2010-2621

2010-07-0220:30:01
CWE-20
web.nvd.nist.gov
24
cve-2010-2621
qsslsocketbackendprivate
transmit function
qt 4.6.3
denial of service
infinite loop
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.169 Low

EPSS

Percentile

96.1%

The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.

Affected configurations

NVD
Node
digiaqtRange4.6.3
OR
qtqtMatch4.0.0
OR
qtqtMatch4.0.1
OR
qtqtMatch4.1.0
OR
qtqtMatch4.1.1
OR
qtqtMatch4.1.2
OR
qtqtMatch4.1.3
OR
qtqtMatch4.1.4
OR
qtqtMatch4.1.5
OR
qtqtMatch4.2.0
OR
qtqtMatch4.2.1
OR
qtqtMatch4.2.3
OR
qtqtMatch4.3.0
OR
qtqtMatch4.3.1
OR
qtqtMatch4.3.2
OR
qtqtMatch4.3.3
OR
qtqtMatch4.3.4
OR
qtqtMatch4.3.5
OR
qtqtMatch4.4.0
OR
qtqtMatch4.4.1
OR
qtqtMatch4.4.2
OR
qtqtMatch4.4.3
OR
qtqtMatch4.5.0
OR
qtqtMatch4.5.1
OR
qtqtMatch4.5.2
OR
qtqtMatch4.5.3
OR
qtqtMatch4.6.0
OR
qtqtMatch4.6.0rc1
OR
qtqtMatch4.6.1
OR
qtqtMatch4.6.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.5 Medium

AI Score

Confidence

Low

0.169 Low

EPSS

Percentile

96.1%