CVE-2012-5624
Ubuntu Security Notice USN-1723-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.
El objeto XMLHttpRequest en Qt anterior a v4.8.4 permite la redirección http al fichero scheme, lo que permite llevar a atacantes de hombre-en-medio (man-in-the-middle) forzar la lectura de ficheros locales arbitrarios y posiblemente obtener información sensible mediante un fichero: URL para una aplicación QML.
Richard J. Moore and Peter Hartmann discovered that Qt allowed redirecting requests from http to file schemes. If an attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information. This issue only affected Ubuntu 11.10, Ubuntu 12.04 LTS, and Ubuntu 12.10. Stephen Cheng discovered that Qt may report incorrect errors when ssl certificate verification fails. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-24 CVE Reserved
- 2013-02-14 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://lists.qt-project.org/pipermail/announce/2012-November/000014.html | Mailing List | |
http://qt.gitorious.org/qt/qt/commit/96311def2466dd44de64d77a1c815b22fbf68f71 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2012/12/04/8 | Mailing List |
|
https://bugzilla.redhat.com/show_bug.cgi?id=883415 | X_refsource_misc | |
https://codereview.qt-project.org/#change%2C40034 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2013-01/msg00034.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2013-01/msg00045.html | 2023-11-07 | |
http://lists.opensuse.org/opensuse-updates/2013-01/msg00048.html | 2023-11-07 | |
http://secunia.com/advisories/52217 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-1723-1 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digia Search vendor "Digia" | Qt Search vendor "Digia" for product "Qt" | <= 4.8.3 Search vendor "Digia" for product "Qt" and version " <= 4.8.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 1.41 Search vendor "Qt" for product "Qt" and version "1.41" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 1.42 Search vendor "Qt" for product "Qt" and version "1.42" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 1.43 Search vendor "Qt" for product "Qt" and version "1.43" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 1.44 Search vendor "Qt" for product "Qt" and version "1.44" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 1.45 Search vendor "Qt" for product "Qt" and version "1.45" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 2.0.0 Search vendor "Qt" for product "Qt" and version "2.0.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 2.0.1 Search vendor "Qt" for product "Qt" and version "2.0.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 2.0.2 Search vendor "Qt" for product "Qt" and version "2.0.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.0 Search vendor "Qt" for product "Qt" and version "3.3.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.1 Search vendor "Qt" for product "Qt" and version "3.3.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.2 Search vendor "Qt" for product "Qt" and version "3.3.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.3 Search vendor "Qt" for product "Qt" and version "3.3.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.4 Search vendor "Qt" for product "Qt" and version "3.3.4" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.5 Search vendor "Qt" for product "Qt" and version "3.3.5" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 3.3.6 Search vendor "Qt" for product "Qt" and version "3.3.6" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.0.0 Search vendor "Qt" for product "Qt" and version "4.0.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.0.1 Search vendor "Qt" for product "Qt" and version "4.0.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.1.0 Search vendor "Qt" for product "Qt" and version "4.1.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.1.1 Search vendor "Qt" for product "Qt" and version "4.1.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.1.2 Search vendor "Qt" for product "Qt" and version "4.1.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.1.3 Search vendor "Qt" for product "Qt" and version "4.1.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.1.4 Search vendor "Qt" for product "Qt" and version "4.1.4" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.1.5 Search vendor "Qt" for product "Qt" and version "4.1.5" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.2.0 Search vendor "Qt" for product "Qt" and version "4.2.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.2.1 Search vendor "Qt" for product "Qt" and version "4.2.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.2.3 Search vendor "Qt" for product "Qt" and version "4.2.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.3.0 Search vendor "Qt" for product "Qt" and version "4.3.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.3.1 Search vendor "Qt" for product "Qt" and version "4.3.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.3.2 Search vendor "Qt" for product "Qt" and version "4.3.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.3.3 Search vendor "Qt" for product "Qt" and version "4.3.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.3.4 Search vendor "Qt" for product "Qt" and version "4.3.4" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.3.5 Search vendor "Qt" for product "Qt" and version "4.3.5" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.4.0 Search vendor "Qt" for product "Qt" and version "4.4.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.4.1 Search vendor "Qt" for product "Qt" and version "4.4.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.4.2 Search vendor "Qt" for product "Qt" and version "4.4.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.4.3 Search vendor "Qt" for product "Qt" and version "4.4.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.5.0 Search vendor "Qt" for product "Qt" and version "4.5.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.5.1 Search vendor "Qt" for product "Qt" and version "4.5.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.5.2 Search vendor "Qt" for product "Qt" and version "4.5.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.5.3 Search vendor "Qt" for product "Qt" and version "4.5.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.0 Search vendor "Qt" for product "Qt" and version "4.6.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.0 Search vendor "Qt" for product "Qt" and version "4.6.0" | rc1 |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.1 Search vendor "Qt" for product "Qt" and version "4.6.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.2 Search vendor "Qt" for product "Qt" and version "4.6.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.3 Search vendor "Qt" for product "Qt" and version "4.6.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.4 Search vendor "Qt" for product "Qt" and version "4.6.4" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.5 Search vendor "Qt" for product "Qt" and version "4.6.5" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.6.5 Search vendor "Qt" for product "Qt" and version "4.6.5" | rc |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.0 Search vendor "Qt" for product "Qt" and version "4.7.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.1 Search vendor "Qt" for product "Qt" and version "4.7.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.2 Search vendor "Qt" for product "Qt" and version "4.7.2" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.3 Search vendor "Qt" for product "Qt" and version "4.7.3" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.4 Search vendor "Qt" for product "Qt" and version "4.7.4" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.5 Search vendor "Qt" for product "Qt" and version "4.7.5" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.6 Search vendor "Qt" for product "Qt" and version "4.7.6" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.7.6 Search vendor "Qt" for product "Qt" and version "4.7.6" | rc |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.8.0 Search vendor "Qt" for product "Qt" and version "4.8.0" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.8.1 Search vendor "Qt" for product "Qt" and version "4.8.1" | - |
Affected
| ||||||
Qt Search vendor "Qt" | Qt Search vendor "Qt" for product "Qt" | 4.8.2 Search vendor "Qt" for product "Qt" and version "4.8.2" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 10.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "10.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 11.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "11.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
|