FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0691

This CVE name corresponds to:

Entered Topic
2004-08-22 qt -- image loader vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2004-0691
Phase Assigned(20040713)

Description

Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code.

References

Source Reference
BUGTRAQ 20040818 CESA-2004-004: qt
DEBIAN DSA-542
SUNALERT 201610
SUSE SUSE-SA:2004:027
REDHAT RHSA-2004:414
GENTOO GLSA-200408-20
MANDRAKE MDKSA-2004:085
OVAL oval:org.mitre.oval:def:9485
XF qt-bmp-bo(17040)