CVE-2013-0254
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
06/02/2013
Last modified:
11/04/2025
Description
The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.
Impact
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:qt:qt:1.41:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:1.42:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:1.43:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:1.44:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:1.45:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:2.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:2.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:qt:qt:3.3.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00014.html
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00015.html
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00019.html
- http://lists.qt-project.org/pipermail/announce/2013-February/000023.html
- http://rhn.redhat.com/errata/RHSA-2013-0669.html
- https://bugzilla.redhat.com/show_bug.cgi?id=907425
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00014.html
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00015.html
- http://lists.opensuse.org/opensuse-updates/2013-03/msg00019.html
- http://lists.qt-project.org/pipermail/announce/2013-February/000023.html
- http://rhn.redhat.com/errata/RHSA-2013-0669.html
- https://bugzilla.redhat.com/show_bug.cgi?id=907425