CVE Vulnerabilities

CVE-2007-0242

Published: Apr 03, 2007 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

Affected Software

Name Vendor Start Version End Version
Qt Qt 3.3.8 (including) 3.3.8 (including)
Qt Qt 4.2.3 (including) 4.2.3 (including)

References