CVE Vulnerabilities

CVE-2013-0254

Published: Feb 06, 2013 | Modified: Jun 16, 2021
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

Affected Software

Name Vendor Start Version End Version
Qt Qt 1.41 (including) 1.41 (including)
Qt Qt 1.42 (including) 1.42 (including)
Qt Qt 1.43 (including) 1.43 (including)
Qt Qt 1.44 (including) 1.44 (including)
Qt Qt 1.45 (including) 1.45 (including)
Qt4-x11 Ubuntu devel *
Qt4-x11 Ubuntu hardy *
Qt4-x11 Ubuntu lucid *
Qt4-x11 Ubuntu oneiric *
Qt4-x11 Ubuntu precise *
Qt4-x11 Ubuntu quantal *
Qt4-x11 Ubuntu upstream *
Red Hat Enterprise Linux 6 RedHat qt-1:4.6.2-26.el6_4 *

References