<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>187465</bug_id>
          
          <creation_ts>2007-08-02 06:52 0000</creation_ts>
          <short_desc>x11-libs/qt-3: possible remote code execution (CVE-2007-3388)</short_desc>
          <delta_ts>2007-08-30 18:48:01 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <bug_file_loc>https://rhn.redhat.com/errata/RHSA-2007-0721.html</bug_file_loc>
          
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>meax@huicht.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>alpha@gentoo.org</cc>
    
    <cc>amd64@gentoo.org</cc>
    
    <cc>ia64@gentoo.org</cc>
    
    <cc>mips@gentoo.org</cc>
    
    <cc>ppc64@gentoo.org</cc>
    
    <cc>ppc@gentoo.org</cc>
    
    <cc>qt@gentoo.org</cc>
    
    <cc>sparc@gentoo.org</cc>
    
    <cc>x86@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>meax@huicht.org</who>
            <bug_when>2007-08-02 06:52:04 0000</bug_when>
            <thetext>&quot;... Several format string flaws were found in Qt error message handling. If an
application linked against Qt created an error message from user supplied
data in a certain way, it could lead to a denial of service or possibly
allow the execution of arbitrary code. (CVE-2007-3388) ...&quot;
from https://rhn.redhat.com/errata/RHSA-2007-0721.html

Trolltech advisory:
http://trolltech.com/company/newsroom/announcements/press.2007-07-27.7503755960

patch:
http://dist.trolltech.com/developer/download/170529.diff

thanks.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-08-02 16:47:26 0000</bug_when>
            <thetext>To quote Dirk Müller from the KDE packager list:

In case you&apos;ve missed it: I&apos;ve added a patch for Qt4 as well to qt-copy. While 
TT claims that none of those are exploitable, I disagree and believe that 
some of them are indeed possible to exploit (though only in uninteresting 
ways as far as I investigated).


so qt-3.3.8-r3 and qt-4.3.0-r1 are in cvs now. Please go for it arch teams.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2007-08-02 16:52:08 0000</bug_when>
            <thetext>I thought there was already an open bug on this...

Anyway, arch teams note that the patch only modifies some debugging output statments via qWarning calls, so this should have absolutely no impact on stability whatsoever.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-08-02 17:13:52 0000</bug_when>
            <thetext>(In reply to comment #2)
&gt; I thought there was already an open bug on this...

There is - once again restricted!? The issue was on the packager list on monday and in the public for at least 30 hours, so I thought you did not have the time and went ahead. :)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>caleb@gentoo.org</who>
            <bug_when>2007-08-02 17:16:27 0000</bug_when>
            <thetext>you&apos;re right, I didn&apos;t, so it&apos;s no problem.  :)

I just seem to remember it being a dupe.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-08-02 18:19:44 0000</bug_when>
            <thetext>

*** This bug has been marked as a duplicate of bug 185446 ***</thetext>
          </long_desc>
      
    </bug>

</bugzilla>