PT-2007-7502 · Qt+1 · Qt3-Linguist+38

Dirk Mueller

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2007-4137

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libqt3-mt-dev versions prior to 3.3.8 libqt3c102-mt-ibase versions prior to 3.3.8 qt3-dev-tools versions prior to 3.3.8 libqt3c102-mt-mysql versions prior to 3.3.8 libqt3c102-mt-psql versions prior to 3.3.8 libqt3c102-mt-odbc versions prior to 3.3.8 qt3-designer versions prior to 3.3.8 qt3-dev-tools-embedded versions prior to 3.3.8 libqt3-dev versions prior to 3.3.8 libqt3-mt-psql versions prior to 3.3.8 qt-designer-3.3.3 versions prior to 3.3.8 qt-devel-docs-3.3.6 versions prior to 3.3.8 qt-3.3.6 versions prior to 3.3.8 qt3-examples versions prior to 3.3.8 qt3-qtconfig versions prior to 3.3.8 libqt3c102-mt-sqlite versions prior to 3.3.8 libqt3c102-mt-psql versions prior to 3.3.8 qt-x11-free-dbg versions prior to 3.3.8 libqt3-mt-ibase versions prior to 3.3.8 qt-config-3.3.6 versions prior to 3.3.8 libqt3-compat-headers versions prior to 3.3.8 libqt3c102-ibase versions prior to 3.3.8 qt-designer-3.3.6 versions prior to 3.3.8 qt (versions prior to 3.3.8-r4) libqt3-mt-odbc versions prior to 3.3.8 libqt3-mt versions prior to 3.3.8 qt-devel-3.3.6 versions prior to 3.3.8 libqt3-mt-sqlite versions prior to 3.3.8 libqt3-headers versions prior to 3.3.8 libqt3c102-mt versions prior to 3.3.8 qt3-dev-tools-compat versions prior to 3.3.8 libqt3-mt-mysql versions prior to 3.3.8 qt3-apps-dev versions prior to 3.3.8 qt3-linguist versions prior to 3.3.8 qt-config-3.3.3 versions prior to 3.3.8 qt-devel-3.3.3 versions prior to 3.3.8 qt-3.3.3 versions prior to 3.3.8 qt3-doc versions prior to 3.3.8 libqt3c102 versions prior to 3.3.8 libqt3c102-odbc versions prior to 3.3.8
Description The issue is related to multiple vulnerabilities in various Qt packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. According to the information provided, the vulnerabilities are present in various Qt packages, including libqt3-mt-dev, libqt3c102-mt-ibase, qt3-dev-tools, and others. The exploitation of these vulnerabilities can result in a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow.
Recommendations For each affected version, update to a version 3.3.8 or later to resolve the issue. As a temporary workaround, consider disabling the QUtf8Decoder::toUnicode function until a patch is available. Restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using the vulnerable packages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2015-02985
BDU:2015-02986
BDU:2015-02987
BDU:2015-02988
BDU:2015-02989
BDU:2015-02990
BDU:2015-02991
BDU:2015-02992
BDU:2015-02993
BDU:2015-02994
BDU:2015-02995
BDU:2015-02996
BDU:2015-02997
BDU:2015-02998
BDU:2015-02999
BDU:2015-03000
BDU:2015-03001
BDU:2015-03002
BDU:2015-03003
BDU:2015-03004
BDU:2015-03005
BDU:2015-03006
BDU:2015-03007
BDU:2015-03008
BDU:2015-03009
BDU:2015-03010
BDU:2015-03011
BDU:2015-03012
BDU:2015-03013
BDU:2015-03014
BDU:2015-03015
BDU:2015-03016
BDU:2015-03017
BDU:2015-03018
BDU:2015-06485
BDU:2015-06486
BDU:2015-06487
BDU:2015-06488
BDU:2015-06489
BDU:2015-06490
BDU:2015-06491
BDU:2015-06492
BDU:2015-06493
BDU:2015-09594
CVE-2007-4137
DSA-1426-1
RHSA-2007:0883
RHSA-2007_0883

Affected Products

Red Hat
Libqt3-Compat-Headers
Libqt3-Dev
Libqt3-Headers
Libqt3-Mt
Libqt3-Mt-Dev
Libqt3-Mt-Ibase
Libqt3-Mt-Mysql
Libqt3-Mt-Odbc
Libqt3-Mt-Psql
Libqt3-Mt-Sqlite
Libqt3C102
Libqt3C102-Ibase
Libqt3C102-Mt
Libqt3C102-Mt-Ibase
Libqt3C102-Mt-Mysql
Libqt3C102-Mt-Odbc
Libqt3C102-Mt-Sqlite
Libqt3C102-Odbc
Qt
Qt-3.3.3
Qt-3.3.6
Qt-Config-3.3.3
Qt-Config-3.3.6
Qt-Designer-3.3.3
Qt-Designer-3.3.6
Qt-Devel-3.3.3
Qt-Devel-3.3.6
Qt-Devel-Docs-3.3.6
Qt-X11-Free-Dbg
Qt3-Apps-Dev
Qt3-Designer
Qt3-Dev-Tools
Qt3-Dev-Tools-Compat
Qt3-Dev-Tools-Embedded
Qt3-Doc
Qt3-Examples
Qt3-Linguist
Qt3-Qtconfig