CVE-2007-5965

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
08/01/2008
Last modified:
09/04/2025

Description

QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trolltech:qsslsocket:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:trolltech:qsslsocket:4.3.1:*:*:*:*:*:*:*
cpe:2.3:a:trolltech:qsslsocket:4.3.2:*:*:*:*:*:*:*