PT-2009-6678 · Qt+3 · Libqt4-Sql-Mysql+35

Thierry Zoller

·

Published

1970-01-01

·

Updated

2022-08-09

·

CVE-2009-1698

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apple Safari versions prior to 4.0 iPhone OS versions 1.0 through 2.2.1 iPhone OS for iPod touch versions 1.1 through 2.2.1 kdelibs-3.1.3 libqt4-sql-sqlite2 (affected versions not specified) libqt4-script (affected versions not specified) libqt4-assistant (affected versions not specified) libqt4-dbus (affected versions not specified) kdelibs5 (affected versions not specified) libqt4-sql-sqlite (affected versions not specified) libqt4-sql-ibase (affected versions not specified) libqt4-network (affected versions not specified) libqt4-opengl-dev (affected versions not specified) libqt4-sql-psql (affected versions not specified) libqt4-xmlpatterns (affected versions not specified) libqt4-sql (affected versions not specified) libqt4-gui (affected versions not specified) qt4-designer (affected versions not specified) libqt4-sql-mysql (affected versions not specified) kdelibs-bin (affected versions not specified) libqt4-xmlpatterns-dbg (affected versions not specified) libqt4-dev (affected versions not specified) libqt4-core (affected versions not specified) kdelibs5-data (affected versions not specified) qt4-demos (affected versions not specified) qt4-dev-tools (affected versions not specified) qt4-doc (affected versions not specified) libqt4-dbg (affected versions not specified) kdelibs-devel-3.1.3 libqt4-xml (affected versions not specified) libqt4-test (affected versions not specified) libqt4-sql-odbc (affected versions not specified) libqt4-qt3support (affected versions not specified) libqt4-webkit-dbg (affected versions not specified) libqt4-svg (affected versions not specified) kdelibs5-dbg (affected versions not specified) qt4-doc-html (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document. It may lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the issue can be done remotely.
Recommendations For Apple Safari versions prior to 4.0, update to version 4.0 or later. For iPhone OS versions 1.0 through 2.2.1, update to a version later than 2.2.1. For iPhone OS for iPod touch versions 1.1 through 2.2.1, update to a version later than 2.2.1. For kdelibs-3.1.3, kdelibs-devel-3.1.3, and other affected packages, update to a version that is not vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability for the rest of the affected software.

Exploit

Fix

RCE

DoS

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2015-02146
BDU:2015-02614
BDU:2015-02615
BDU:2015-02616
BDU:2015-02617
BDU:2015-02905
BDU:2015-02907
BDU:2015-02908
BDU:2015-02909
BDU:2015-02910
BDU:2015-02911
BDU:2015-02912
BDU:2015-02913
BDU:2015-02914
BDU:2015-04034
BDU:2015-04035
BDU:2015-04036
BDU:2015-04037
BDU:2015-04038
BDU:2015-04039
BDU:2015-04040
BDU:2015-04041
BDU:2015-04042
BDU:2015-04043
BDU:2015-04044
BDU:2015-04045
BDU:2015-04046
BDU:2015-04047
BDU:2015-04048
BDU:2015-04049
BDU:2015-04050
BDU:2015-04051
BDU:2015-04052
BDU:2015-04053
BDU:2015-04054
BDU:2015-04055
BDU:2015-04056
BDU:2015-04057
BDU:2015-07268
BDU:2015-07273
BDU:2015-08518
BDU:2015-08519
CVE-2009-1698
DSA-1867-1
DSA-1868-1
DSA-1950-1
DSA-1988-1
RHSA-2009:1127
RHSA-2009:1128
RHSA-2009_1127

Affected Products

Red Hat
Safari
Ios
Kdelibs
Kdelibs-Bin
Kdelibs5
Kdelibs5-Data
Kdelibs5-Dbg
Libqt4-Assistant
Libqt4-Core
Libqt4-Dbg
Libqt4-Dbus
Libqt4-Dev
Libqt4-Gui
Libqt4-Network
Libqt4-Opengl-Dev
Libqt4-Qt3Support
Libqt4-Script
Libqt4-Sql
Libqt4-Sql-Ibase
Libqt4-Sql-Mysql
Libqt4-Sql-Odbc
Libqt4-Sql-Psql
Libqt4-Sql-Sqlite
Libqt4-Sql-Sqlite2
Libqt4-Svg
Libqt4-Test
Libqt4-Webkit-Dbg
Libqt4-Xml
Libqt4-Xmlpatterns
Libqt4-Xmlpatterns-Dbg
Qt4-Demos
Qt4-Designer
Qt4-Dev-Tools
Qt4-Doc
Qt4-Doc-Html