NASLDB: USN-1504-1 : qt4-x11 vulnerabilities
General
ID: 59957
Name: USN-1504-1 : qt4-x11 vulnerabilities
Summary: Checks dpkg output for updated package(s)
Credits: –
Classification
Risk: –
CVSS: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Ubuntu Local Security Checks
Type: Local
Description
It was discovered that Qt did not properly handle wildcard domain
names or IP addresses in the Common Name field of X.509 certificates.
An attacker could exploit this to perform a man in the middle attack
to view sensitive information or alter encrypted communications. This
issue only affected Ubuntu 10.04 LTS. (CVE-2010-5076)
A heap-based buffer overflow was discovered in the HarfBuzz module.
If a user were tricked into opening a crafted font file in a Qt
application, an attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2011-3193)
It was discovered that Qt did not properly handle greyscale TIFF
images. If a Qt application could be made to process a crafted TIFF
file, an attacker could cause a denial of service. (CVE-2011-3194)
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2010-5076
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: 2012/07/11
Plugin Release: 2012/07/12
Plugin
Version: 1.1
Filename: ubuntu_USN-1504-1.nasl
Filesize: 3562 bytes
MD5 Hash: cf4b3bf74eab2c6766127e80021cddcb
Identification: Host/local_checks_enabled
Require Keys: Host/Ubuntu", "Host/Ubuntu/release", "Host/Debian/dpkg-l
Dependencies: "ssh_get_info.nasl"
Copyright: –
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













