First published: Fri Aug 03 2007(Updated: )
Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trolltech Qt | <=3.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3388 has a high severity rating due to the potential for remote code execution.
To fix CVE-2007-3388, update Trolltech Qt to version 3.3.8 or later.
CVE-2007-3388 affects Trolltech Qt versions prior to 3.3.8.
Yes, CVE-2007-3388 can be exploited remotely by attackers through specially crafted input.
Exploiting CVE-2007-3388 can allow an attacker to execute arbitrary code on the vulnerable system.