CVE Vulnerabilities

CVE-2007-0242

Published: Apr 03, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

Affected Software

NameVendorStart VersionEnd Version
QtQt3.3.8 (including)3.3.8 (including)
QtQt4.2.3 (including)4.2.3 (including)
Red Hat Enterprise Linux 2.1RedHatqt-1:2.3.1-14.EL2*
Red Hat Enterprise Linux 3RedHatqt-1:3.1.2-17.RHEL3*
Red Hat Enterprise Linux 4RedHatqt-1:3.3.3-13.RHEL4*
Red Hat Enterprise Linux 4RedHatkdelibs-6:3.3.1-9.el4*
Red Hat Enterprise Linux 5RedHatqt-1:3.3.6-23.el5*
Red Hat Enterprise Linux 5RedHatkdelibs-6:3.5.4-13.el5*
Red Hat Enterprise Linux 5RedHatqt4-0:4.2.1-1.el5_7.1*
KdelibsUbuntudapper*
KdelibsUbuntudevel*
KdelibsUbuntuedgy*
KdelibsUbuntufeisty*
Qt-x11-freeUbuntudapper*
Qt-x11-freeUbuntudevel*
Qt-x11-freeUbuntuedgy*
Qt-x11-freeUbuntufeisty*
Qt4-x11Ubuntudevel*

References