Описание
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2007-3388
- https://issues.rpath.com/browse/RPL-1597
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9690
- http://bugs.gentoo.org/show_bug.cgi?id=185446
- http://dist.trolltech.com/developer/download/170529.diff
- http://fedoranews.org/updates/FEDORA-2007-221.shtml
- http://fedoranews.org/updates/FEDORA-2007-703.shtml
- http://secunia.com/advisories/24460
- http://secunia.com/advisories/26264
- http://secunia.com/advisories/26284
- http://secunia.com/advisories/26291
- http://secunia.com/advisories/26295
- http://secunia.com/advisories/26298
- http://secunia.com/advisories/26306
- http://secunia.com/advisories/26385
- http://secunia.com/advisories/26607
- http://secunia.com/advisories/26804
- http://secunia.com/advisories/26852
- http://secunia.com/advisories/26882
- http://secunia.com/advisories/27996
- http://secunia.com/advisories/28021
- http://security.gentoo.org/glsa/glsa-200712-08.xml
- http://securitytracker.com/id?1018485
- http://support.avaya.com/elmodocs2/security/ASA-2007-388.htm
- http://trolltech.com/company/newsroom/announcements/press.2007-07-27.7503755960
- http://www.debian.org/security/2007/dsa-1426
- http://www.gentoo.org/security/en/glsa/glsa-200708-16.xml
- http://www.gentoo.org/security/en/glsa/glsa-200710-28.xml
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:151
- http://www.novell.com/linux/security/advisories/2007_48_qt3.html
- http://www.redhat.com/support/errata/RHSA-2007-0721.html
- http://www.securityfocus.com/archive/1/475480/30/5550/threaded
- http://www.securityfocus.com/bid/25154
- http://www.slackware.org/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.354168
- http://www.ubuntu.com/usn/usn-495-1
- http://www.vupen.com/english/advisories/2007/2733
EPSS
CVE ID
Связанные уязвимости
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdata ...
EPSS