CVE-2007-0242: XSS
Published Apr 3, 2007
·Updated
The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.
Affected Software
2 affected components
Qt QT=3.3.8
Qt QT=4.2.3
Remediation
Event History
Apr 3, 2007
CVE Published
04:19 PM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0242?
CVE-2007-0242 is classified as a medium severity vulnerability.
2
How do I fix CVE-2007-0242?
To fix CVE-2007-0242, upgrade to a later version of Qt that addresses the vulnerability.
3
What types of attacks can CVE-2007-0242 allow?
CVE-2007-0242 can allow remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks.
4
Which versions of Qt are affected by CVE-2007-0242?
CVE-2007-0242 affects Qt versions 3.3.8 and 4.2.3.
5
What impact does CVE-2007-0242 have on applications?
CVE-2007-0242 can lead to vulnerabilities in applications relying on the affected versions of Qt, potentially allowing execution of harmful scripts.