Name | CVE-2013-0254 |
Description | The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-210-1 |
Debian Bugs | 699870 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
qt4-x11 | source | squeeze | 4:4.6.3-4+squeeze3 | DLA-210-1 | ||
qt4-x11 | source | (unstable) | 4:4.8.2+dfsg-11 | 699870 |
possible follow-up problem if patch is applied: http://bugs.debian.org/700530
but bug in xorg server, needs checking