CVE-2010-5076: Input Validation
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5076?
CVE-2010-5076 is considered a medium severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2010-5076?
To fix CVE-2010-5076, upgrade your Qt version to 4.7.0-rc1 or higher.
Which software is affected by CVE-2010-5076?
CVE-2010-5076 affects various versions of Qt prior to 4.7.0-rc1, including 4.0.0 to 4.6.4.
What type of attack does CVE-2010-5076 allow?
CVE-2010-5076 allows man-in-the-middle attackers to spoof arbitrary SSL servers using a crafted X.509 certificate.
How can I identify if I am vulnerable to CVE-2010-5076?
You can identify vulnerability to CVE-2010-5076 by checking if you are using a version of Qt prior to 4.7.0-rc1.