Bug 248417 - (CVE-2007-3388) CVE-2007-3388 qt3 format string flaw
CVE-2007-3388 qt3 format string flaw
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 248418 248419 248420 248421 248422
  Show dependency treegraph
Reported: 2007-07-16 14:19 EDT by Josh Bressers
Modified: 2010-02-15 23:54 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-01-15 11:34:11 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Proposed upstream patch (6.36 KB, patch)
2007-07-16 14:24 EDT, Josh Bressers
no flags Details | Diff

  None (edit)
Description Josh Bressers 2007-07-16 14:19:47 EDT
A format string flaw has been found in the way QT's QTextEdit constructs error

This flaw does not affect QT4, or QT2.  It is only present in QT3.


Red Hat would like to acknowledge Tim Brown of Portcullis Computer Security and Dirk Mueller for these issues.
Comment 2 Josh Bressers 2007-07-16 14:24:04 EDT
Created attachment 159351 [details]
Proposed upstream patch

This patch also fixes several additional format string flaws.
Comment 4 Josh Bressers 2007-07-16 14:44:29 EDT
Credit for discovering this flaw should go to Tracey Parry of Portcullis
Computer Security Ltd.
Comment 6 Mark J. Cox (Product Security) 2007-07-18 04:28:47 EDT
        embargo set to 20070727 by Trolltech
Comment 9 Josh Bressers 2007-07-31 10:47:46 EDT
This is now public:
Comment 10 Red Hat Product Security 2008-01-15 11:34:11 EST
This issue was addressed in:

Red Hat Enterprise Linux:


Note You need to log in before you can comment on or make changes to this bug.