CVE-2013-0254
Publication date 6 February 2013
Last updated 24 July 2024
Ubuntu priority
Description
The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.
Status
Package | Ubuntu Release | Status |
---|---|---|
qt4-x11 | 12.10 quantal |
Fixed 4:4.8.3+dfsg-0ubuntu3.1
|
12.04 LTS precise |
Fixed 4:4.8.1-0ubuntu4.4
|
|
11.10 oneiric |
Fixed 4:4.7.4-0ubuntu8.3
|
|
10.04 LTS lucid |
Fixed 4:4.6.2-0ubuntu5.6
|
|
8.04 LTS hardy | Ignored end of life |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1723-1
- Qt vulnerabilities
- 14 February 2013