---------------------------------------------------------------------
Fedora Update Notification
FEDORA-2004-271
2004-08-23
---------------------------------------------------------------------

Product     : Fedora Core 2
Name        : qt
Version     : 3.3.3
Release     : 0.1
Summary     : The shared library for the Qt GUI toolkit.
Description :
Qt is a GUI software toolkit which simplifies the task of writing and
maintaining GUI (Graphical User Interface) applications
for the X Window System.

Qt is written in C++ and is fully object-oriented.

This package contains the shared library needed to run qt
applications, as well as the README files for qt.

---------------------------------------------------------------------
Update Information:

During a security audit, Chris Evans discovered a heap overflow in the BMP
image decoder in Qt versions prior to 3.3.3. An attacker could create a
carefully crafted BMP file in such a way that it would cause an application
linked with Qt to crash or possibly execute arbitrary code when the file
was opened by a victim. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG
decoders in Qt versions prior to 3.3.3. An attacker could create carefully
crafted image files in such a way that it could cause an application linked
against Qt to crash when the file was opened by a victim. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the
names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain
backported patches and are not vulnerable to these issues.
---------------------------------------------------------------------
* Thu Aug 19 2004 Than Ngo <than@redhat.com> 1:3.3.3-0.1

- update to 3.3.3, fix image buffer overflows

* Thu Jul 29 2004 Than Ngo <than@redhat.com> 1:3.3.2-2.1

- fix overflow vulnerability, thanks to trolltech


---------------------------------------------------------------------
This update can be downloaded from:
    

d7d133c9fb84ec203b4a96451397777c  SRPMS/qt-3.3.3-0.1.src.rpm
3069582d6fc4e3472a9b578b9031b613  x86_64/qt-3.3.3-0.1.x86_64.rpm
f827f011c8284069da86aa977399e16a  x86_64/qt-devel-3.3.3-0.1.x86_64.rpm
a98f9ad7b50bd5757f4d70cfe4e6b43d  x86_64/qt-ODBC-3.3.3-0.1.x86_64.rpm
8d9305bbd849ad85033830adf8ce69d8  x86_64/qt-MySQL-3.3.3-0.1.x86_64.rpm
17eee4ff21a9afeab3af2e711fa350df  x86_64/qt-PostgreSQL-3.3.3-0.1.x86_64.rpm
c62a0d58db076e8aae868959410240fa  x86_64/qt-designer-3.3.3-0.1.x86_64.rpm
db3d362f1ccdc2643b0dad1494d3dae2  
x86_64/debug/qt-debuginfo-3.3.3-0.1.x86_64.rpm
64f43afd922842ea5847d2549e989ffa  i386/qt-3.3.3-0.1.i386.rpm
88f2edc217d4d6ef27974756aac2d590  i386/qt-devel-3.3.3-0.1.i386.rpm
0688e0872934c4dc365f496953e9b5cc  i386/qt-ODBC-3.3.3-0.1.i386.rpm
c0208bd84c45a11a2a90e738cd3f4232  i386/qt-MySQL-3.3.3-0.1.i386.rpm
7e6fa694913d8f03d88ba49dfbedf8e8  i386/qt-PostgreSQL-3.3.3-0.1.i386.rpm
67cfecbeb2b1528a1224daca29a4fd6c  i386/qt-designer-3.3.3-0.1.i386.rpm
822a56de23158db0bfe1979ba064420a  i386/debug/qt-debuginfo-3.3.3-0.1.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.
---------------------------------------------------------------------

Fedora: qt buffer overflow (Core 2)

August 23, 2004
During a security audit, Chris Evans discovered a heap overflow in the BMPimage decoder in Qt versions prior to 3.3.3.

Summary

Qt is a GUI software toolkit which simplifies the task of writing and

maintaining GUI (Graphical User Interface) applications

for the X Window System.

Qt is written in C++ and is fully object-oriented.

This package contains the shared library needed to run qt

applications, as well as the README files for qt.

Update Information:

During a security audit, Chris Evans discovered a heap overflow in the BMP image decoder in Qt versions prior to 3.3.3. An attacker could create a carefully crafted BMP file in such a way that it would cause an application linked with Qt to crash or possibly execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0691 to this issue.

Additionally, various flaws were discovered in the GIF, XPM, and JPEG decoders in Qt versions prior to 3.3.3. An attacker could create carefully crafted image files in such a way that it could cause an application linked against Qt to crash when the file was opened by a victim. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2004-0692 and CAN-2004-0693 to these issues.

Users of Qt should update to these updated packages which contain backported patches and are not vulnerable to these issues. * Thu Aug 19 2004 Than Ngo <than@redhat.com> 1:3.3.3-0.1

- update to 3.3.3, fix image buffer overflows

* Thu Jul 29 2004 Than Ngo <than@redhat.com> 1:3.3.2-2.1

- fix overflow vulnerability, thanks to trolltech


This update can be downloaded from:


d7d133c9fb84ec203b4a96451397777c SRPMS/qt-3.3.3-0.1.src.rpm 3069582d6fc4e3472a9b578b9031b613 x86_64/qt-3.3.3-0.1.x86_64.rpm f827f011c8284069da86aa977399e16a x86_64/qt-devel-3.3.3-0.1.x86_64.rpm a98f9ad7b50bd5757f4d70cfe4e6b43d x86_64/qt-ODBC-3.3.3-0.1.x86_64.rpm 8d9305bbd849ad85033830adf8ce69d8 x86_64/qt-MySQL-3.3.3-0.1.x86_64.rpm 17eee4ff21a9afeab3af2e711fa350df x86_64/qt-PostgreSQL-3.3.3-0.1.x86_64.rpm c62a0d58db076e8aae868959410240fa x86_64/qt-designer-3.3.3-0.1.x86_64.rpm db3d362f1ccdc2643b0dad1494d3dae2 x86_64/debug/qt-debuginfo-3.3.3-0.1.x86_64.rpm 64f43afd922842ea5847d2549e989ffa i386/qt-3.3.3-0.1.i386.rpm 88f2edc217d4d6ef27974756aac2d590 i386/qt-devel-3.3.3-0.1.i386.rpm 0688e0872934c4dc365f496953e9b5cc i386/qt-ODBC-3.3.3-0.1.i386.rpm c0208bd84c45a11a2a90e738cd3f4232 i386/qt-MySQL-3.3.3-0.1.i386.rpm 7e6fa694913d8f03d88ba49dfbedf8e8 i386/qt-PostgreSQL-3.3.3-0.1.i386.rpm 67cfecbeb2b1528a1224daca29a4fd6c i386/qt-designer-3.3.3-0.1.i386.rpm 822a56de23158db0bfe1979ba064420a i386/debug/qt-debuginfo-3.3.3-0.1.i386.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.

Change Log

References

Fedora Update Notification FEDORA-2004-271 2004-08-23 Product : Fedora Core 2 Name : qt Version : 3.3.3 Release : 0.1 Summary : The shared library for the Qt GUI toolkit. Description : Qt is a GUI software toolkit which simplifies the task of writing and maintaining GUI (Graphical User Interface) applications for the X Window System. Qt is written in C++ and is fully object-oriented. This package contains the shared library needed to run qt applications, as well as the README files for qt.

Update Instructions

Severity
Product : Fedora Core 2
Name : qt
Version : 3.3.3
Release : 0.1
Summary : The shared library for the Qt GUI toolkit.

Related News