CVE-2010-2621: Input Validation
The QSslSocketBackendPrivate::transmit function in srcnetworksslqsslsocketopenssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2621?
CVE-2010-2621 is classified as a denial of service vulnerability that can lead to an infinite loop.
How do I fix CVE-2010-2621?
To address CVE-2010-2621, upgrade to a version of Qt later than 4.6.3 where the vulnerability has been resolved.
What versions of Qt are affected by CVE-2010-2621?
CVE-2010-2621 affects Qt versions 4.6.3 and earlier, including all versions from 4.0.0 to 4.6.2.
Can CVE-2010-2621 be exploited remotely?
Yes, CVE-2010-2621 can be exploited by remote attackers through a malformed request, leading to a denial of service.
What impact does CVE-2010-2621 have on applications using Qt?
Applications using affected versions of Qt may experience service interruption due to the infinite loop triggered by the vulnerability.