CVE-2010-2621

Digia QT < 4.6.3 - Improper Input Validation

Title source: rule
STIX 2.1

Description

The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Luigi Auriemma · textdosmultiple
https://www.exploit-db.com/exploits/14268

References (9)

Core 9
Core References
Exploit x_refsource_misc
http://aluigi.org/poc/qtsslame.zip
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46410
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1657
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/41250
Various Sources vendor-advisory x_refsource_suse
https://hermes.opensuse.org/messages/12056605
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/65860
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40389
Various Sources x_refsource_misc
http://aluigi.org/adv/qtsslame-adv.txt

Scores

EPSS 0.1200
EPSS Percentile 93.8%

Details

CWE
CWE-20
Status published
Products (29)
digia/qt < 4.6.3
qt/qt 4.0.0
qt/qt 4.0.1
qt/qt 4.1.0
qt/qt 4.1.1
qt/qt 4.1.2
qt/qt 4.1.3
qt/qt 4.1.4
qt/qt 4.1.5
qt/qt 4.2.0
... and 19 more
Published Jul 02, 2010
Tracked Since Feb 18, 2026