Family: SuSE Local Security Checks --> Category: infos
SUSE-SA:2004:027: qt3/qt3-non-mt/qt3-32bit/qt3-static Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the qt3 packages
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory SUSE-SA:2004:027
The QT-library is an environment for GUI-programming and is used in
various well-known projects, like KDE.
There is a heap overflow in the BMP image format parser. An
attacker, exploiting this flaw, would need to be able to coerce
a local user or program to process a specially crafted image
file. Upon successful exploitation, the attacker would be able
to execute arbitrary code.
In addition, there are 2 distinct flaws within the XPM parser
which, when exploited, lead to a Denial of Service (DoS).
Solution : http://www.suse.de/security/2004_27_qt3.html
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.