Git-Url: http://git.frugalware.org/gitweb/gitweb.cgi?p=homepage-ng.git;a=commitdiff;h=aa7128b9a73932cf863c2e673a3fbad94b125c5f
commit aa7128b9a73932cf863c2e673a3fbad94b125c5f Author: voroskoi <[EMAIL PROTECTED]> Date: Mon Oct 1 09:48:37 2007 +0200 FSA283-qt4 diff --git a/frugalware/xml/security.xml b/frugalware/xml/security.xml index bc35a13..fd2079b 100644 --- a/frugalware/xml/security.xml +++ b/frugalware/xml/security.xml @@ -27,6 +27,18 @@ <fsas> <fsa> + <id>283</id> + <date>2007-10-01</date> + <author>voroskoi</author> + <package>qt4</package> + <vulnerable>4.2.3-2terminus1</vulnerable> + <unaffected>4.2.3-2terminus2</unaffected> + <bts>http://bugs.frugalware.org/task/2422</bts> + <cve>http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4137</cve> + <desc>A vulnerability has been reported in Qt, which can potentially be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library. + The vulnerability is caused due to an off-by-one error within the "QUtf8Decoder::toUnicode()" function ("QUtf8Codec::convertToUnicode()" in Qt 4.x) in codecs/qutfcodec.cpp. This can be exploited to cause a one-byte heap-based buffer overflow via a specially crafted unicode string.</desc> + </fsa> + <fsa> <id>282</id> <date>2007-10-01</date> <author>voroskoi</author> _______________________________________________ Frugalware-git mailing list [email protected] http://frugalware.org/mailman/listinfo/frugalware-git
