Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-08T23:14:10

Updated: 2020-10-05T18:06:15

Reserved: 2020-06-08T00:00:00


Link: CVE-2020-13962

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2020-06-09T00:15:10.123

Modified: 2023-11-07T03:17:04.313


Link: CVE-2020-13962

JSON object: View

cve-icon Redhat Information

No data.