CVE-2012-5624: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 11.10 only; version 12.04 only; version 12.10 only
  • Digia Qt: up to and including 4.8.3
  • Qt Qt: version 1.41 only; version 1.42 only; version 1.43 only; version 1.44 only; version 1.45 only; version 2.0.0 only; …

Published 2013-02-24. Last modified 2026-06-16.