CVE-2010-5076

QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
digiaqt
𝑥
≤ 4.6.4
qtqt
4.0.0
qtqt
4.0.1
qtqt
4.1.0
qtqt
4.1.1
qtqt
4.1.2
qtqt
4.1.3
qtqt
4.1.4
qtqt
4.1.5
qtqt
4.2.0
qtqt
4.2.1
qtqt
4.2.3
qtqt
4.3.0
qtqt
4.3.1
qtqt
4.3.2
qtqt
4.3.3
qtqt
4.3.4
qtqt
4.3.5
qtqt
4.4.0
qtqt
4.4.1
qtqt
4.4.2
qtqt
4.4.3
qtqt
4.5.0
qtqt
4.5.1
qtqt
4.5.2
qtqt
4.5.3
qtqt
4.6.0
qtqt
4.6.0:rc1
qtqt
4.6.1
qtqt
4.6.2
qtqt
4.6.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt4-x11
hardy
ignored
lucid
Fixed 4:4.6.2-0ubuntu5.4
released
natty
not-affected
oneiric
not-affected
precise
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
phonon-backend-gstreamer
RHEL 6
1:4.6.2-24.el6
fixed
qt
RHEL 6
1:4.6.2-24.el6
fixed
qt-demos
RHEL 6
1:4.6.2-24.el6
fixed
qt-devel
RHEL 6
1:4.6.2-24.el6
fixed
qt-doc
RHEL 6
1:4.6.2-24.el6
fixed
qt-examples
RHEL 6
1:4.6.2-24.el6
fixed
qt-mysql
RHEL 6
1:4.6.2-24.el6
fixed
qt-odbc
RHEL 6
1:4.6.2-24.el6
fixed
qt-postgresql
RHEL 6
1:4.6.2-24.el6
fixed
qt-sqlite
RHEL 6
1:4.6.2-24.el6
fixed
qt-x11
RHEL 6
1:4.6.2-24.el6
fixed