LWN.net Logo

qt: confusing SSL error messages

Package(s):qt CVE #(s):CVE-2012-6093
Created:January 14, 2013 Updated:February 7, 2013
Description: From the Red Hat bugzilla:

A security flaw was found in the way QSslSocket implementation of the Qt, a software toolkit for applications development, performed certificate verification callbacks, when Qt libraries were used with different OpenSSL version than the one, they were compiled against. In such scenario, this would result in a connection error, but with the SSL error list to contain QSslError:NoError instead of proper reason of the error. This might result in a confusing error being presented to the end users, possibly encouraging them to ignore the SSL errors for the site the connection was initiated against.

Alerts:
Fedora FEDORA-2013-0277 2013-01-12
Fedora FEDORA-2013-0199 2013-01-23
Fedora FEDORA-2013-0270 2013-01-24
openSUSE openSUSE-SU-2013:0204-1 2013-01-29
openSUSE openSUSE-SU-2013:0211-1 2013-01-30
openSUSE openSUSE-SU-2013:0256-1 2013-02-07
Ubuntu USN-1723-1 2013-02-14
Mageia MGASA-2013-0053 2013-02-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds