Qt 'XmlHttpRequest' Object Insecure Redirection Information Disclosure Vulnerability
BID:56807
Info
Qt 'XmlHttpRequest' Object Insecure Redirection Information Disclosure Vulnerability
| Bugtraq ID: | 56807 |
| Class: | Design Error |
| CVE: |
CVE-2012-5624 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2012 12:00AM |
| Updated: | May 07 2015 05:04PM |
| Credit: | Richard J. Moore (Westpoint Ltd) and Peter Hartmann (RIM) |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Digia Qt 4.8.3 |
| Not Vulnerable: |
Digia Qt 4.8.4 |
Discussion
Qt 'XmlHttpRequest' Object Insecure Redirection Information Disclosure Vulnerability
Qt is prone to an information-disclosure vulnerability that affects QML-based applications.
Attackers can exploit this issue to cause QML-based applications to read content from arbitrary local files through man-in-the-middle attacks. This allows attackers to obtain sensitive information that may aid in launching further attacks.
Versions prior to Qt 4.8.4 are vulnerable.
Qt is prone to an information-disclosure vulnerability that affects QML-based applications.
Attackers can exploit this issue to cause QML-based applications to read content from arbitrary local files through man-in-the-middle attacks. This allows attackers to obtain sensitive information that may aid in launching further attacks.
Versions prior to Qt 4.8.4 are vulnerable.
Exploit / POC
Qt 'XmlHttpRequest' Object Insecure Redirection Information Disclosure Vulnerability
Attackers can use readily available network utilities.
Attackers can use readily available network utilities.
Solution / Fix
Qt 'XmlHttpRequest' Object Insecure Redirection Information Disclosure Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
Qt 'XmlHttpRequest' Object Insecure Redirection Information Disclosure Vulnerability
References:
References:
- [Announce] Qt Project Security Advisory: QML XmlHttpRequest Insecure Redirection (Richard J. Moore)
- Change I7a3cec66: Make the rules for redirects a bit stricter. (Richard J. Moore)
- Vendor Homepage (Digia)