The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-02-06T11:00:00
Updated: 2024-08-06T14:18:09.656Z
Reserved: 2012-12-06T00:00:00
Link: CVE-2013-0254
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-02-06T12:05:43.647
Modified: 2024-11-21T01:47:10.020
Link: CVE-2013-0254
Redhat