Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:085: qt3 Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the qt3 package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:085 (qt3).
Chris Evans discovered a heap-based overflow in the QT library when handling
8-bit RLE encoded BMP files. This vulnerability could allow for the compromise
of the account used to view or browse malicious BMP files. On subsequent
investigation, it was also found that the handlers for XPM, GIF, and JPEG image
types were also faulty.
These problems affect all applications that use QT to handle image files, such
as QT-based image viewers, the Konqueror web browser, and others.
The updated packages have been patched to correct these problems.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:085
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.