CVE Vulnerabilities

CVE-2013-0254

Published: Feb 06, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

Affected Software

NameVendorStart VersionEnd Version
QtQt1.41 (including)1.41 (including)
QtQt1.42 (including)1.42 (including)
QtQt1.43 (including)1.43 (including)
QtQt1.44 (including)1.44 (including)
QtQt1.45 (including)1.45 (including)
Red Hat Enterprise Linux 6RedHatqt-1:4.6.2-26.el6_4*
Qt4-x11Ubuntudevel*
Qt4-x11Ubuntuhardy*
Qt4-x11Ubuntulucid*
Qt4-x11Ubuntuoneiric*
Qt4-x11Ubuntuprecise*
Qt4-x11Ubuntuquantal*
Qt4-x11Ubuntuupstream*

References