CVE Vulnerabilities

CVE-2007-3388

Published: Aug 03, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.

Affected Software

Name Vendor Start Version End Version
Qt Trolltech * 3.3.7 (including)
Red Hat Enterprise Linux 3 RedHat qt-1:3.1.2-16.RHEL3 *
Red Hat Enterprise Linux 4 RedHat qt-1:3.3.3-11.RHEL4 *
Red Hat Enterprise Linux 5 RedHat qt-1:3.3.6-21.el5 *
Qt-x11-free Ubuntu dapper *
Qt-x11-free Ubuntu devel *
Qt-x11-free Ubuntu edgy *
Qt-x11-free Ubuntu feisty *

References