Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Qt4: Denial of Service
Posted by Benjamin D. Thomas
malicious people to potentially compromise a user's system.
--==============54629654=Content-Type: multipart/alternative; boundary 1636c5b3523ad161046e7ecc02
--001636c5b3523ad161046e7ecc02
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-102 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-07-12
Severity: 4
Type: Remote
------------------------------------------------------------------------
Summary
======
A vulnerability has been reported in Qt4, which can be exploited by
malicious people to potentially compromise a user's system.
Description
==========
The vulnerability is caused due to a boundary error in WebKit when
processing SVGList objects. This can be exploited to trigger a memory
corruption when visiting a malicious web page.
Affected packages:
Pardus 2008:
qt4, all before 4.4.3-55-18
qt4-designer, all before 4.4.3-55-18
qt4-doc, all before 4.4.3-55-16
qt4-linguist, all before 4.4.3-55-18
qt4-sql-ibase, all before 4.4.3-55-4
qt4-sql-mysql, all before 4.4.3-55-18
qt4-sql-odbc, all before 4.4.3-55-18
qt4-sql-postgresql, all before 4.4.3-55-18
qt4-sql-sqlite, all before 4.4.3-55-18
Resolution
=========
There are update(s) for qt4, qt4-designer, qt4-doc, qt4-linguist,
qt4-sql-ibase, qt4-sql-mysql, qt4-sql-odbc, qt4-sql-postgresql,
qt4-sql-sqlite. You can update them via Package Manager or with a single
command from console:
pisi up qt4 qt4-designer qt4-doc qt4-linguist qt4-sql-ibase
qt4-sql-mysql qt4-sql-odbc qt4-sql-postgresql qt4-sql-sqlite
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id™15
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0945