Submitted by MartinPitt on Fri, 2007-08-03 10:39
Referenced CVEs:
CVE-2007-3388
Description:
===========================================================
Ubuntu Security Notice USN-495-1 August 03, 2007
qt-x11-free vulnerability
CVE-2007-3388
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libqt3-mt 3:3.3.6-1ubuntu6.3
Ubuntu 6.10:
libqt3-mt 3:3.3.6-3ubuntu3.2
Ubuntu 7.04:
libqt3-mt 3:3.3.8really3.3.7-0ubuntu5.1
After a standard system upgrade you should restart your KDE session to
to effect the necessary changes.
Details follow:
Several format string vulnerabilities have been discovered in Qt
warning messages. By causing an application to process specially
crafted input data which triggered Qt warnings, this could be
exploited to execute arbitrary code with the privilege of the user
running the application.


