CVE-2006-4811
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
Does this matter?
Lower severity and a low EPSS score (4.25%). Track it; it rarely justifies an emergency change on its own.
Description
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.25% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- qt/qt · redhat/kdelibs
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20061002-01-P
- ftp://patches.sgi.com/support/free/security/advisories/20061101-01-P
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=210742
- http://lists.suse.com/archive/suse-security-announce/2006-Oct/0006.html
- http://secunia.com/advisories/22380Patch, Vendor Advisory
- http://secunia.com/advisories/22397Vendor Advisory
- http://secunia.com/advisories/22479Patch, Vendor Advisory
- http://secunia.com/advisories/22485Patch, Vendor Advisory
- http://secunia.com/advisories/22492Patch, Vendor Advisory
- http://secunia.com/advisories/22520Patch, Vendor Advisory
- http://secunia.com/advisories/22579Vendor Advisory
- http://secunia.com/advisories/22586Vendor Advisory
- http://secunia.com/advisories/22589Vendor Advisory
- http://secunia.com/advisories/22645Vendor Advisory
- http://secunia.com/advisories/22738Vendor Advisory
- http://secunia.com/advisories/22890Vendor Advisory
- http://secunia.com/advisories/22929Vendor Advisory
- http://secunia.com/advisories/24347Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200611-02.xml
- http://security.gentoo.org/glsa/glsa-200703-06.xml
- http://securitytracker.com/id?1017084
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.483634
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:186
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:187
- http://www.redhat.com/support/errata/RHSA-2006-0720.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0725.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/449173/100/0/threaded
- http://www.securityfocus.com/bid/20599
- http://www.trolltech.com/company/newsroom/announcements/press.2006-10-19.5434451733
- http://www.ubuntu.com/usn/usn-368-1Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.