Submitted by KeesCook on Tue, 2007-09-18 20:05
Referenced CVEs:
CVE-2007-4137
Description:
===========================================================
Ubuntu Security Notice USN-513-1 September 18, 2007
qt-x11-free vulnerability
CVE-2007-4137
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libqt3-mt 3:3.3.6-1ubuntu6.4
Ubuntu 6.10:
libqt3-mt 3:3.3.6-3ubuntu3.3
Ubuntu 7.04:
libqt3-mt 3:3.3.8really3.3.7-0ubuntu5.2
After a standard system upgrade you need to restart your session to
effect the necessary changes.
Details follow:
Dirk Mueller discovered that UTF8 strings could be made to cause a small
buffer overflow. A remote attacker could exploit this by sending specially
crafted strings to applications that use the Qt3 library for UTF8 processing,
potentially leading to arbitrary code execution with user privileges, or a
denial of service.


