DescriptionQSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SR:2008:002, published Fri, 25 Jan 2008 16:00:00 +0000
SUSE Timeline for this CVECVE page created: Tue Jul 9 16:36:29 2013
CVE page last modified: Fri Oct 7 12:45:38 2022