The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2013-02-06T11:00:00
Updated: 2013-03-23T09:00:00
Reserved: 2012-12-06T00:00:00
Link: CVE-2013-0254
JSON object: View
NVD Information
Status : Modified
Published: 2013-02-06T12:05:43.647
Modified: 2021-06-16T12:44:00.727
Link: CVE-2013-0254
JSON object: View
Redhat Information
No data.
CWE