Release date:
Updated on:
Affected Systems:
Qt-project Qt 4.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-5624
Qt is a cross-platform application framework.
The XMLHttpRequest object implementation in QT provides functions similar to the XMLHttpRequest object in the browser. However, the implementation of the Object in versions earlier than Qt 4.8.4 does not properly consider the same origin policy. QT's implementation of this object causes man-in-the-middle attackers to redirect http requests to a file: URL, causing leakage of sensitive information.
<* Source: Richard J. Moore (rich@kde.org)
Link: http://secunia.com/advisories/51655/
Http://lists.qt-project.org/pipermail/announce/2012-November/000014.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Qt-project
----------
Qt-project has released a Security Bulletin (000014) and corresponding patches for this purpose:
000014: Qt Project Security Advisory: QML XmlHttpRequest Insecure Redirection
Link: http://lists.qt-project.org/pipermail/announce/2012-November/000014.html
Patch download: https://codereview.qt-project.org/#change,40034