CVE-2007-3388

Description

From CVE.org

Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cpp in QTextEdit in Trolltech Qt 3 before 3.3.8 20070727 allow remote attackers to execute arbitrary code via format string specifiers in text used to compose an error message.

Acknowledgements

Red Hat would like to thank Dirk Mueller and Tim Brown (Portcullis Computer Security) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.