1 results (0.003 seconds)

CVSS: 4.3EPSS: 4%CPEs: 3EXPL: 0

08 Jan 2008 — QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user. QSslSocket de Trolltech Qt 4.3.0 hasta 4.3.2 no verifica apropiadamente certificados SSL, lo cual facilita a atacantes remotos engañar a un usuario para que acepte un certificado de servidor inválido para un servic... • http://secunia.com/advisories/28228 • CWE-264: Permissions, Privileges, and Access Controls •