LWN.net Logo

qt: multiple vulnerabilities

Package(s):qt CVE #(s):CVE-2010-5076 CVE-2011-3922
Created:June 20, 2012 Updated:July 10, 2012
Description: From the Red Hat advisory:

A buffer overflow flaw was found in the harfbuzz module in Qt. If a user loaded a specially-crafted font file with an application linked against Qt, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2011-3922)

A flaw was found in the way Qt handled X.509 certificates with IP address wildcards. An attacker able to obtain a certificate with a Common Name containing an IP wildcard could possibly use this flaw to impersonate an SSL server to client applications that are using Qt. This update also introduces more strict handling for hostname wildcard certificates by disallowing the wildcard character to match more than one hostname component. (CVE-2010-5076)

Alerts:
Red Hat RHSA-2012:0880-04 2012-06-20
Oracle ELSA-2012-0880 2012-07-02
Scientific Linux SL-qt-20120709 2012-07-09
CentOS CESA-2012:0880 2012-07-10
Ubuntu USN-1504-1 2012-07-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds