Trolltech Qt Assistant Default Port Unauthorized Access Weakness
BID:5833
Info
Trolltech Qt Assistant Default Port Unauthorized Access Weakness
| Bugtraq ID: | 5833 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2002 12:00AM |
| Updated: | Sep 30 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Rohit Sharma <[email protected]>. |
| Vulnerable: |
Trolltech Qt Assistant 1.0 |
| Not Vulnerable: | |
Discussion
Trolltech Qt Assistant Default Port Unauthorized Access Weakness
A weakness has been reported for the Qt Assistant. The Qt Assistant is a browser for the Qt documentation and is typically used in conjuntion with Qt Designer. Reportedly, the Qt Assistant opens a port for communication with Qt Designer which can be accessed remotely.
An attacker can exploit this weakness by connecting to a vulnerable system and make numerous requests for HTML pages. This may cause the Qt Assistant from responding to legitimate requests in a timely manner.
A weakness has been reported for the Qt Assistant. The Qt Assistant is a browser for the Qt documentation and is typically used in conjuntion with Qt Designer. Reportedly, the Qt Assistant opens a port for communication with Qt Designer which can be accessed remotely.
An attacker can exploit this weakness by connecting to a vulnerable system and make numerous requests for HTML pages. This may cause the Qt Assistant from responding to legitimate requests in a timely manner.
Exploit / POC
Trolltech Qt Assistant Default Port Unauthorized Access Weakness
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Trolltech Qt Assistant Default Port Unauthorized Access Weakness
Solution:
Reportedly, this vulnerability is no longer present in Qt 3.1. Users should contact the vendor about obtaining upgrades.
Solution:
Reportedly, this vulnerability is no longer present in Qt 3.1. Users should contact the vendor about obtaining upgrades.