Title : Trolltech Qt "QString::fromUtf8()" Sequence Decoding Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-1212 CVE ID : CVE-2007-0242
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-03
Technical Description
A vulnerability has been identified in Trolltech Qt, which could be exploited by attackers to bypass security restrictions. This issue is due to an input validation error in the "QString::fromUtf8()" [tools/qstring.cpp] function that does not reject overly long UTF-8 sequences, which could be exploited to e.g. conduct directory traversal attacks or cause arbitrary scripting code to be executed in the security context of an application linked against a vulnerable library.