Trolltech QT Local Code Execution Vulnerability
BID:12695
Info
Trolltech QT Local Code Execution Vulnerability
| Bugtraq ID: | 12695 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 01 2005 12:00AM |
| Updated: | Mar 01 2005 12:00AM |
| Credit: | Tavis Ormandy is credited with the discovery of this issue. |
| Vulnerable: |
Trolltech Qt 3.3.4 Trolltech Qt 3.3.3 Trolltech Qt 3.3.2 Trolltech Qt 3.3.1 Trolltech Qt 3.3 .0 Trolltech Qt 3.2.3 Trolltech Qt 3.2.1 Trolltech Qt 3.1.2 Trolltech Qt 3.1.1 Trolltech Qt 3.1 Trolltech Qt 3.0.5 Trolltech Qt 3.0.3 Trolltech Qt 3.0 |
| Not Vulnerable: | |
Discussion
Trolltech QT Local Code Execution Vulnerability
A local code execution vulnerability affects Trolltech QT. These issues are due to a failure of the application to secure local dynamically loaded libraries.
An attacker may leverage this issue to execute arbitrary code in the context of an unsuspecting user that activates a QT derived product; this will facilitate privilege escalation.
A local code execution vulnerability affects Trolltech QT. These issues are due to a failure of the application to secure local dynamically loaded libraries.
An attacker may leverage this issue to execute arbitrary code in the context of an unsuspecting user that activates a QT derived product; this will facilitate privilege escalation.
Exploit / POC
Trolltech QT Local Code Execution Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Trolltech QT Local Code Execution Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200503-01 dealing with this issue. Gentoo advises that all Qt users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=x11-libs/qt-3.3.4-r2"
For more information, please see the referenced Gentoo advisory.
Solution:
Gentoo Linux has released advisory GLSA 200503-01 dealing with this issue. Gentoo advises that all Qt users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=x11-libs/qt-3.3.4-r2"
For more information, please see the referenced Gentoo advisory.
References
Trolltech QT Local Code Execution Vulnerability
References:
References:
- QT Homepage (Trolltech)
- Trolltech Homepage (Trolltech)