Qt Creator Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:43672
Info
Qt Creator Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 43672 |
| Class: | Design Error |
| CVE: |
CVE-2010-3374 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 03 2010 12:00AM |
| Updated: | Dec 19 2014 12:56AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Trolltech Qt Creator 2.0 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Gentoo Linux |
| Not Vulnerable: |
Trolltech Qt Creator 2.0.1 |
Discussion
Qt Creator Insecure Library Loading Arbitrary Code Execution Vulnerability
Qt Creator is prone to an insecure library loading vulnerability.
An attacker can exploit this issue by placing a malicious library file in the current working directory and enticing a legitimate user to run QT or the QT Creator application. Successful exploitation will allow an attacker to execute arbitrary code in the context of the user running the affected application.
Qt Creator 2.0.0 and prior are affected.
Qt Creator is prone to an insecure library loading vulnerability.
An attacker can exploit this issue by placing a malicious library file in the current working directory and enticing a legitimate user to run QT or the QT Creator application. Successful exploitation will allow an attacker to execute arbitrary code in the context of the user running the affected application.
Qt Creator 2.0.0 and prior are affected.
Exploit / POC
Qt Creator Insecure Library Loading Arbitrary Code Execution Vulnerability
Attackers can exploit the issue using standard commands.
Attackers can exploit the issue using standard commands.
Solution / Fix
Qt Creator Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1
Mandriva Linux Mandrake 2010.1 x86_64
Mandriva Linux Mandrake 2010.0 x86_64
Mandriva Linux Mandrake 2010.0
Solution:
Updates are available. Please see the references for more information.
Mandriva Linux Mandrake 2010.1
-
Mandriva qt-creator-1.3.1-3.2mdv2010.1.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva qt-creator-doc-1.3.1-3.2mdv2010.1.i586.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.1 x86_64
-
Mandriva qt-creator-1.3.1-3.2mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva qt-creator-doc-1.3.1-3.2mdv2010.1.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva lib64aggregation1-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64cplusplus1-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64extensionsystem1-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64qtconcurrent1-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64utils1-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva qt-creator-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva qt-creator-doc-1.2.1-2.2mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2010.0
-
Mandriva libaggregation1-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libcplusplus1-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libextensionsystem1-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libqtconcurrent1-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libutils1-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva qt-creator-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva qt-creator-doc-1.2.1-2.2mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
References
Qt Creator Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References: