Bug 269001 (CVE-2007-4137) - CVE-2007-4137 QT off by one buffer overflow
Summary: CVE-2007-4137 QT off by one buffer overflow
Alias: CVE-2007-4137
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 269061 269081 269101 269121 269141 269161 292941 292951
TreeView+ depends on / blocked
Reported: 2007-08-30 20:24 UTC by Josh Bressers
Modified: 2019-09-29 12:20 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2008-01-15 16:33:36 UTC

Attachments (Terms of Use)
Proposed patch for QT3 (338 bytes, patch)
2007-08-30 20:25 UTC, Josh Bressers
no flags Details | Diff
Proposed patch for QT4 (467 bytes, patch)
2007-08-30 20:26 UTC, Josh Bressers
no flags Details | Diff

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2007:0883 0 normal SHIPPED_LIVE Important: qt security update 2008-01-08 00:03:59 UTC

Description Josh Bressers 2007-08-30 20:24:08 UTC
Dirk Mueller reported an off by one buffer overflow flaw in the way QT parses
certain unicode strings.

To quote Dirk:

    I`ve found a off-by-one buffer overflow in QUtf8Decoder::toUnicode().  
    It is not exploitable with Qt 4.x or above because there is an  
    additional QChar(0) being allocated in QString, however it is still a  
    bug there, as the array returned by utf16() etc is no longer  
    terminated properly.

Comment 2 Josh Bressers 2007-08-30 20:25:42 UTC
Created attachment 181821 [details]
Proposed patch for QT3

Comment 3 Josh Bressers 2007-08-30 20:26:03 UTC
Created attachment 181841 [details]
Proposed patch for QT4

Comment 11 Mark J. Cox 2007-09-13 08:57:28 UTC
public, removing embargo

Comment 13 Red Hat Product Security 2008-01-15 16:33:36 UTC
This issue was addressed in:

Red Hat Enterprise Linux:


Note You need to log in before you can comment on or make changes to this bug.