QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qsslsocket | Trolltech | 4.3.0 (including) | 4.3.0 (including) |
Qsslsocket | Trolltech | 4.3.1 (including) | 4.3.1 (including) |
Qsslsocket | Trolltech | 4.3.2 (including) | 4.3.2 (including) |
Qt4-x11 | Ubuntu | gutsy | * |