CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
93.0%
Package : qt4-x11
Version : 4:4.6.3-4+squeeze3
CVE ID : CVE-2013-0254 CVE-2015-0295 CVE-2015-1858 CVE-2015-1859
CVE-2015-1860
Debian Bug : 779550 783133
This update fixes multiple security issues in the Qt library.
CVE-2013-0254
The QSharedMemory class uses weak permissions (world-readable and
world-writable) for shared memory segments, which allows local users
to read sensitive information or modify critical program data, as
demonstrated by reading a pixmap being sent to an X server.
CVE-2015-0295 / CVE-2015-1858 / CVE-2015-1859 / CVE-2015-1860
Denial of service (via segmentation faults) through crafted
images (BMP, GIF, ICO).
–
Raphaël Hertzog ◈ Debian Developer
Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/
Attachment:
signature.asc
Description: Digital signature