Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade x11-libs/qt. | Oct 30, 2017 | Aug 3, 2007 |
| Oracle_linux | — | Upgrade qt-develUpgrade qt-designerUpgrade qt-odbcUpgrade qtUpgrade qt-devel-docsUpgrade qt-mysqlUpgrade qt-configUpgrade qt-postgresql | Oct 16, 2024 | Aug 3, 2007 |
| Suse | — | Upgrade qt3-devel-toolsUpgrade qt3-x86Upgrade qt3-develUpgrade qt3Upgrade qt3-devel-docUpgrade qt3-devel-tools-32bitUpgrade qt3-devel-32bitUpgrade qt3-32bit | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libqt3-mt | Nov 8, 2024 | Aug 3, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub