qt: "/../" injection
| Package(s): | qt | CVE #(s): | CVE-2007-0242 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Created: | April 4, 2007 | Updated: | September 13, 2007 | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Description: | Andreas Nolden discovered a bug in qt3, where the UTF8 decoder does not reject overlong sequences, which can cause "/../" injection or (in the case of konqueror) a "<script>" tag injection. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||
