Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow. NOTE: Qt 4 has the same error in the QUtf8Codec::convertToUnicode function, but it is not exploitable.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade x11-libs/qt. | Oct 30, 2017 | Sep 18, 2007 |
| Oracle_linux | — | Upgrade qt-configUpgrade qt-postgresqlUpgrade qt-odbcUpgrade qt-mysqlUpgrade qtUpgrade qt-develUpgrade qt-devel-docsUpgrade qt-designer | Oct 16, 2024 | Sep 18, 2007 |
| Suse | — | Upgrade qt3-devel-docUpgrade qt3Upgrade qt3-devel-32bitUpgrade qt3-devel-toolsUpgrade qt3-develUpgrade qt3-32bitUpgrade qt3-x86Upgrade qt3-devel-tools-32bit | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libqt3-mt | Nov 8, 2024 | Sep 18, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub