Qt 'QtCore.dll' DLL Loading Arbitrary Code Execution Vulnerability
BID:43363
Info
Qt 'QtCore.dll' DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 43363 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2010 12:00AM |
| Updated: | Sep 27 2010 08:00PM |
| Credit: | This issue was reported by multiple unknown sources. |
| Vulnerable: |
Trolltech Qt Creator 2.0.1 Trolltech Qt 4.6.3 Trolltech Qt 4.6.2 Trolltech Qt 4.6.1 Trolltech Qt 4.6 Trolltech Qt 4.5.2 Trolltech Qt 4.5.1 Trolltech Qt 4.4.3 Trolltech Qt 4.3.3 Trolltech Qt 4.3.2 Trolltech Qt 4.3.1 Trolltech Qt 4.3 Trolltech Qt 4.2.3 Trolltech Qt 4.2.1 Trolltech Qt 4.1.5 Trolltech Qt 4.1.4 Trolltech Qt 4.1 Trolltech Qt 4.0.1 Trolltech Qt 4.5 Trolltech Qt 4.2 Trolltech Qt 4.1 |
| Not Vulnerable: | |
Discussion
Qt 'QtCore.dll' DLL Loading Arbitrary Code Execution Vulnerability
Qt is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use a vulnerable application created with Qt to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Qt 4.6.3 is vulnerable; other versions may also be affected.
Qt is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use a vulnerable application created with Qt to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
Qt 4.6.3 is vulnerable; other versions may also be affected.
Exploit / POC
Qt 'QtCore.dll' DLL Loading Arbitrary Code Execution Vulnerability
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Qt 'QtCore.dll' DLL Loading Arbitrary Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Qt 'QtCore.dll' DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- QT Homepage (Trolltech)
- Microsoft Security Advisory (2269637) (Microsoft)