---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-270
2004-08-23
---------------------------------------------------------------------

Product     : Fedora Core 1
Name        : qt
Version     : 3.1.2
Release     : 14.2
Summary     : The shared library for the Qt GUI toolkit.
Description :
Qt is a GUI software toolkit which simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications
for the X Window System.

Qt is written in C++ and is fully object-oriented.

This package contains the shared library needed to run qt
applications, as well as the README files for qt.

---------------------------------------------------------------------
Update Information:

During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3. An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.
---------------------------------------------------------------------
* Thu Aug 19 2004 Than Ngo <than@redhat.com> 1:3.1.2-14.2

- fix image buffer overflows

* Thu Jul 29 2004 Than Ngo <than@redhat.com> 1:3.1.2-14.1

- fix overflow vulnerability, thanks to trolltech


---------------------------------------------------------------------
This update can be downloaded from:
    

c763ada78b47f3bc72a06e26b929c8c4  SRPMS/qt-3.1.2-14.2.src.rpm
f86739a73579c5b6b698a873b4446d22  x86_64/qt-3.1.2-14.2.x86_64.rpm
6110ba73b9bbce08df7f8529d8185a51  x86_64/qt-devel-3.1.2-14.2.x86_64.rpm
86aad3b91aef11b01da1c816cccaffbe  x86_64/qt-ODBC-3.1.2-14.2.x86_64.rpm
fb94f45a83cabdfb45751fd293be2ccc  x86_64/qt-MySQL-3.1.2-14.2.x86_64.rpm
d4077aa9c95b065b89512e8937d3895d  x86_64/qt-PostgreSQL-3.1.2-14.2.x86_64.rpm
2dce1a5d23a9f763f34b0f180cf5d5a1  x86_64/qt-designer-3.1.2-14.2.x86_64.rpm
b34a6cc0e2af6a58241bdb9e25618919  
x86_64/debug/qt-debuginfo-3.1.2-14.2.x86_64.rpm
aca527b50ab8b71bbb7e4a6e93278173  i386/qt-3.1.2-14.2.i386.rpm
d800a0e0f24c5c748c0e6d4d0cbc766d  i386/qt-devel-3.1.2-14.2.i386.rpm
8dc18024573a730fd625a54c4283be63  i386/qt-ODBC-3.1.2-14.2.i386.rpm
62785195ce484b82c388c3bc38992895  i386/qt-MySQL-3.1.2-14.2.i386.rpm
586469add7922ac224dcdc24819ce284  i386/qt-PostgreSQL-3.1.2-14.2.i386.rpm
263b2d0b195ab4869be6f4074df1c728  i386/qt-designer-3.1.2-14.2.i386.rpm
fb8ebc4323f3d36032d757a365a9bbbc  
i386/debug/qt-debuginfo-3.1.2-14.2.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------

Fedora: qt buffer overflow (Core 1)

August 23, 2004
During a security audit, Chris Evans discovered a heap overflow in the BMPimage decoder in Qt versions prior to 3.3.3.

Summary

Qt is a GUI software toolkit which simplifies the task of writing and

maintaining GUI (Graphical User Interface) applications

for the X Window System.

Qt is written in C++ and is fully object-oriented.

This package contains the shared library needed to run qt

applications, as well as the README files for qt.

Update Information:

During a security audit, Chris Evans discovered a heap overflow in the BMP image decoder in Qt versions prior to 3.3.3. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with Qt to crash or possibly execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG decoders in Qt versions prior to 3.3.3. An attacker could create carefully crafted image files in such a way that it could cause an application linked against Qt to crash when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain backported patches and are not vulnerable to these issues. * Thu Aug 19 2004 Than Ngo <than@redhat.com> 1:3.1.2-14.2

- fix image buffer overflows

* Thu Jul 29 2004 Than Ngo <than@redhat.com> 1:3.1.2-14.1

- fix overflow vulnerability, thanks to trolltech


This update can be downloaded from:


c763ada78b47f3bc72a06e26b929c8c4 SRPMS/qt-3.1.2-14.2.src.rpm f86739a73579c5b6b698a873b4446d22 x86_64/qt-3.1.2-14.2.x86_64.rpm 6110ba73b9bbce08df7f8529d8185a51 x86_64/qt-devel-3.1.2-14.2.x86_64.rpm 86aad3b91aef11b01da1c816cccaffbe x86_64/qt-ODBC-3.1.2-14.2.x86_64.rpm fb94f45a83cabdfb45751fd293be2ccc x86_64/qt-MySQL-3.1.2-14.2.x86_64.rpm d4077aa9c95b065b89512e8937d3895d x86_64/qt-PostgreSQL-3.1.2-14.2.x86_64.rpm 2dce1a5d23a9f763f34b0f180cf5d5a1 x86_64/qt-designer-3.1.2-14.2.x86_64.rpm b34a6cc0e2af6a58241bdb9e25618919 x86_64/debug/qt-debuginfo-3.1.2-14.2.x86_64.rpm aca527b50ab8b71bbb7e4a6e93278173 i386/qt-3.1.2-14.2.i386.rpm d800a0e0f24c5c748c0e6d4d0cbc766d i386/qt-devel-3.1.2-14.2.i386.rpm 8dc18024573a730fd625a54c4283be63 i386/qt-ODBC-3.1.2-14.2.i386.rpm 62785195ce484b82c388c3bc38992895 i386/qt-MySQL-3.1.2-14.2.i386.rpm 586469add7922ac224dcdc24819ce284 i386/qt-PostgreSQL-3.1.2-14.2.i386.rpm 263b2d0b195ab4869be6f4074df1c728 i386/qt-designer-3.1.2-14.2.i386.rpm fb8ebc4323f3d36032d757a365a9bbbc i386/debug/qt-debuginfo-3.1.2-14.2.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Change Log

References

Fedora Update Notification FEDORA-2004-270 2004-08-23 Product : Fedora Core 1 Name : qt Version : 3.1.2 Release : 14.2 Summary : The shared library for the Qt GUI toolkit. Description : Qt is a GUI software toolkit which simplifies the task of writing and maintaining GUI (Graphical User Interface) applications for the X Window System. Qt is written in C++ and is fully object-oriented. This package contains the shared library needed to run qt applications, as well as the README files for qt.

Update Instructions

Severity
Product : Fedora Core 1
Name : qt
Version : 3.1.2
Release : 14.2
Summary : The shared library for the Qt GUI toolkit.

Related News