Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Trolltech Qt QSslSocket Class Certificate Verification Security Bypass Vulnerability

Trolltech Qt QSslSocket class is prone to a security-bypass vulnerability because of an unspecified error in the certificate-validation functionality.

Remote attackers can exploit this issue to successfully authenticate to applications using QSslSocket with an unverified spoofed certificate; other attacks may also be possible.

This issue affects Qt 4.3.0, 4.3.1, and 4.3.2.







 

Privacy Statement
Copyright 2009, SecurityFocus