PT-2007-7502 · Qt+1 · Qt3-Linguist+38
Dirk Mueller
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2007-4137
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libqt3-mt-dev versions prior to 3.3.8
libqt3c102-mt-ibase versions prior to 3.3.8
qt3-dev-tools versions prior to 3.3.8
libqt3c102-mt-mysql versions prior to 3.3.8
libqt3c102-mt-psql versions prior to 3.3.8
libqt3c102-mt-odbc versions prior to 3.3.8
qt3-designer versions prior to 3.3.8
qt3-dev-tools-embedded versions prior to 3.3.8
libqt3-dev versions prior to 3.3.8
libqt3-mt-psql versions prior to 3.3.8
qt-designer-3.3.3 versions prior to 3.3.8
qt-devel-docs-3.3.6 versions prior to 3.3.8
qt-3.3.6 versions prior to 3.3.8
qt3-examples versions prior to 3.3.8
qt3-qtconfig versions prior to 3.3.8
libqt3c102-mt-sqlite versions prior to 3.3.8
libqt3c102-mt-psql versions prior to 3.3.8
qt-x11-free-dbg versions prior to 3.3.8
libqt3-mt-ibase versions prior to 3.3.8
qt-config-3.3.6 versions prior to 3.3.8
libqt3-compat-headers versions prior to 3.3.8
libqt3c102-ibase versions prior to 3.3.8
qt-designer-3.3.6 versions prior to 3.3.8
qt (versions prior to 3.3.8-r4)
libqt3-mt-odbc versions prior to 3.3.8
libqt3-mt versions prior to 3.3.8
qt-devel-3.3.6 versions prior to 3.3.8
libqt3-mt-sqlite versions prior to 3.3.8
libqt3-headers versions prior to 3.3.8
libqt3c102-mt versions prior to 3.3.8
qt3-dev-tools-compat versions prior to 3.3.8
libqt3-mt-mysql versions prior to 3.3.8
qt3-apps-dev versions prior to 3.3.8
qt3-linguist versions prior to 3.3.8
qt-config-3.3.3 versions prior to 3.3.8
qt-devel-3.3.3 versions prior to 3.3.8
qt-3.3.3 versions prior to 3.3.8
qt3-doc versions prior to 3.3.8
libqt3c102 versions prior to 3.3.8
libqt3c102-odbc versions prior to 3.3.8
Description
The issue is related to multiple vulnerabilities in various Qt packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. According to the information provided, the vulnerabilities are present in various Qt packages, including libqt3-mt-dev, libqt3c102-mt-ibase, qt3-dev-tools, and others. The exploitation of these vulnerabilities can result in a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow.
Recommendations
For each affected version, update to a version 3.3.8 or later to resolve the issue.
As a temporary workaround, consider disabling the
QUtf8Decoder::toUnicode function until a patch is available.
Restrict access to the vulnerable modules to minimize the risk of exploitation.
Avoid using the vulnerable packages until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Libqt3-Compat-Headers
Libqt3-Dev
Libqt3-Headers
Libqt3-Mt
Libqt3-Mt-Dev
Libqt3-Mt-Ibase
Libqt3-Mt-Mysql
Libqt3-Mt-Odbc
Libqt3-Mt-Psql
Libqt3-Mt-Sqlite
Libqt3C102
Libqt3C102-Ibase
Libqt3C102-Mt
Libqt3C102-Mt-Ibase
Libqt3C102-Mt-Mysql
Libqt3C102-Mt-Odbc
Libqt3C102-Mt-Sqlite
Libqt3C102-Odbc
Qt
Qt-3.3.3
Qt-3.3.6
Qt-Config-3.3.3
Qt-Config-3.3.6
Qt-Designer-3.3.3
Qt-Designer-3.3.6
Qt-Devel-3.3.3
Qt-Devel-3.3.6
Qt-Devel-Docs-3.3.6
Qt-X11-Free-Dbg
Qt3-Apps-Dev
Qt3-Designer
Qt3-Dev-Tools
Qt3-Dev-Tools-Compat
Qt3-Dev-Tools-Embedded
Qt3-Doc
Qt3-Examples
Qt3-Linguist
Qt3-Qtconfig