Vulnerability Description
Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow. NOTE: Qt 4 has the same error in the QUtf8Codec::convertToUnicode function, but it is not exploitable.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Conectiva | Linux | 9.0 |
| Gentoo | Linux | All versions |
| Mandrakesoft | Mandrake Linux | 9.2 |
| Mandrakesoft | Mandrake Linux Corporate Server | 3.0 |
| Redhat | Enterprise Linux | 2.1 |
| Redhat | Linux | 2.1 |
| Ubuntu | Ubuntu Linux | 6.06_lts |
| Trolltech | Qt | 3.0 |
Related Weaknesses (CWE)
References
- ftp://patches.sgi.com/support/free/security/advisories/20070901-01-P.asc
- http://bugs.gentoo.org/show_bug.cgi?id=192472
- http://dist.trolltech.com/developer/download/175791_3.diff
- http://dist.trolltech.com/developer/download/175791_4.diff
- http://fedoranews.org/updates/FEDORA-2007-221.shtml
- http://fedoranews.org/updates/FEDORA-2007-703.shtml
- http://osvdb.org/39384
- http://secunia.com/advisories/26778Vendor Advisory
- http://secunia.com/advisories/26782Vendor Advisory
- http://secunia.com/advisories/26804
- http://secunia.com/advisories/26811Vendor Advisory
- http://secunia.com/advisories/26857
- http://secunia.com/advisories/26868
- http://secunia.com/advisories/26882
- http://secunia.com/advisories/26987
FAQ
What is CVE-2007-4137?
CVE-2007-4137 is a vulnerability with a CVSS score of 7.5 (HIGH). Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-bas...
How severe is CVE-2007-4137?
CVE-2007-4137 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4137?
Check the references section above for vendor advisories and patch information. Affected products include: Conectiva Linux, Gentoo Linux, Mandrakesoft Mandrake Linux, Mandrakesoft Mandrake Linux Corporate Server, Redhat Enterprise Linux.