PT-2004-3709 · Qt · Libqt3-Odbc+3
Published
1970-01-01
·
Updated
2017-10-11
·
CVE-2004-0692
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
qt versions prior to 3.3.3
libqt3-mysql versions (affected versions not specified)
libqt3-odbc versions (affected versions not specified)
qt3-tools versions (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the qt package and its related components, which can lead to a disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The XPM parser in the QT library is specifically vulnerable to a denial of service attack via a malformed image file, causing a null dereference and application crash.
Recommendations
For qt versions prior to 3.3.3, update to version 3.3.3 or later to resolve the issue.
For libqt3-mysql, libqt3-odbc, and qt3-tools, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libqt3-Mysql
Libqt3-Odbc
Qt
Qt3-Tools