USN-495-1: Qt vulnerability

Ubuntu Security Notice USN-495-1

3rd August, 2007

qt-x11-free vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 7.04
  • Ubuntu 6.10
  • Ubuntu 6.06 LTS

Details

Several format string vulnerabilities have been discovered in Qt
warning messages. By causing an application to process specially
crafted input data which triggered Qt warnings, this could be
exploited to execute arbitrary code with the privilege of the user
running the application.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 7.04:
libqt3-mt 3:3.3.8really3.3.7-0ubuntu5.1
Ubuntu 6.10:
libqt3-mt 3:3.3.6-3ubuntu3.2
Ubuntu 6.06 LTS:
libqt3-mt 3:3.3.6-1ubuntu6.3

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system upgrade you should restart your KDE session to
to effect the necessary changes.

References

CVE-2007-3388