CVE-2007-3388
Published: 3 August 2007
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Priority
Status
Package | Release | Status |
---|---|---|
qt-x11-free Launchpad, Ubuntu, Debian |
dapper |
Released
(3.3.6-1ubuntu6.4)
|
edgy |
Released
(3.3.6-3ubuntu3.3)
|
|
feisty |
Released
(3.3.8really3.3.7-0ubuntu5.2)
|
|
upstream |
Needs triage
|
|
qt4-x11 Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
|
edgy |
Not vulnerable
|
|
feisty |
Not vulnerable
|
|
upstream |
Needs triage
|