CVE-2013-0254

NameCVE-2013-0254
DescriptionThe QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-210-1
NVD severitylow (attack range: local)
Debian Bugs699870

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qt4-x11 (PTS)wheezy4:4.8.2+dfsg-11fixed
jessie4:4.8.6+git64-g5dc8b2b+dfsg-3+deb8u1fixed
buster, sid, stretch4:4.8.7+dfsg-11fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qt4-x11source(unstable)4:4.8.2+dfsg-11low699870
qt4-x11sourcesqueeze4:4.6.3-4+squeeze3lowDLA-210-1

Notes

possible follow-up problem if patch is applied: http://bugs.debian.org/700530
but bug in xorg server, needs checking

Search for package or bug name: Reporting problems