Name | CVE-2013-0254 |
Description | The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-210-1 |
Debian Bugs | 699870 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
qt4-x11 (PTS) | jessie, jessie (lts) | 4:4.8.6+git64-g5dc8b2b+dfsg-3+deb8u5 | fixed |
stretch (security) | 4:4.8.7+dfsg-11+deb9u3 | fixed | |
stretch (lts), stretch | 4:4.8.7+dfsg-11+deb9u4 | fixed | |
buster (security), buster, buster (lts) | 4:4.8.7+dfsg-18+deb10u2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
qt4-x11 | source | squeeze | 4:4.6.3-4+squeeze3 | DLA-210-1 | ||
qt4-x11 | source | (unstable) | 4:4.8.2+dfsg-11 | 699870 |
possible follow-up problem if patch is applied: http://bugs.debian.org/700530
but bug in xorg server, needs checking