CVE-2006-4811
published 2006-10-18CVE-2006-4811: Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.25%
89.9th percentile
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| redhat | kdelibs | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-55vc-fmpc-5q9q: Integer overflow in Qt 3
ghsa_unreviewed·2022-05-03
CVE-2006-4811 [MEDIUM] GHSA-55vc-fmpc-5q9q: Integer overflow in Qt 3
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
Ubuntu
Qt vulnerability
vendor_ubuntu·2006-10-24
CVE-2006-4811 Qt vulnerability
Title: Qt vulnerability
Summary: Qt vulnerability
An integer overflow was discovered in Qt's image loader. By processing
a specially crafted image with an application that uses this library
(like Konqueror), a remote attacker could exploit this to execute
arbitrary code with the application's privileges.
Instructions: After a standard system upgrade you need to restart your Desktop
session to effect the necessary changes.
Red Hat
security flaw
vendor_redhat·2006-10-13·CVSS 6.8
CVE-2006-4811 [MEDIUM] security flaw
security flaw
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
No detection rules found.
No public exploits indexed.
ftp://patches.sgi.com/support/free/security/advisories/20061002-01-Pftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=210742http://lists.suse.com/archive/suse-security-announce/2006-Oct/0006.htmlhttp://secunia.com/advisories/22380http://secunia.com/advisories/22397http://secunia.com/advisories/22479http://secunia.com/advisories/22485http://secunia.com/advisories/22492http://secunia.com/advisories/22520http://secunia.com/advisories/22579http://secunia.com/advisories/22586http://secunia.com/advisories/22589http://secunia.com/advisories/22645http://secunia.com/advisories/22738http://secunia.com/advisories/22890http://secunia.com/advisories/22929http://secunia.com/advisories/24347http://security.gentoo.org/glsa/glsa-200611-02.xmlhttp://security.gentoo.org/glsa/glsa-200703-06.xmlhttp://securitytracker.com/id?1017084http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.483634http://www.mandriva.com/security/advisories?name=MDKSA-2006:186http://www.mandriva.com/security/advisories?name=MDKSA-2006:187http://www.redhat.com/support/errata/RHSA-2006-0720.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0725.htmlhttp://www.securityfocus.com/archive/1/449173/100/0/threadedhttp://www.securityfocus.com/bid/20599http://www.trolltech.com/company/newsroom/announcements/press.2006-10-19.5434451733http://www.ubuntu.com/usn/usn-368-1http://www.us.debian.org/security/2006/dsa-1200http://www.vupen.com/english/advisories/2006/4099https://issues.rpath.com/browse/RPL-723https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10218ftp://patches.sgi.com/support/free/security/advisories/20061002-01-Pftp://patches.sgi.com/support/free/security/advisories/20061101-01-Phttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=210742http://lists.suse.com/archive/suse-security-announce/2006-Oct/0006.htmlhttp://secunia.com/advisories/22380http://secunia.com/advisories/22397http://secunia.com/advisories/22479http://secunia.com/advisories/22485http://secunia.com/advisories/22492http://secunia.com/advisories/22520http://secunia.com/advisories/22579http://secunia.com/advisories/22586http://secunia.com/advisories/22589http://secunia.com/advisories/22645http://secunia.com/advisories/22738http://secunia.com/advisories/22890http://secunia.com/advisories/22929http://secunia.com/advisories/24347http://security.gentoo.org/glsa/glsa-200611-02.xmlhttp://security.gentoo.org/glsa/glsa-200703-06.xmlhttp://securitytracker.com/id?1017084http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.483634http://www.mandriva.com/security/advisories?name=MDKSA-2006:186http://www.mandriva.com/security/advisories?name=MDKSA-2006:187http://www.redhat.com/support/errata/RHSA-2006-0720.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0725.htmlhttp://www.securityfocus.com/archive/1/449173/100/0/threadedhttp://www.securityfocus.com/bid/20599http://www.trolltech.com/company/newsroom/announcements/press.2006-10-19.5434451733http://www.ubuntu.com/usn/usn-368-1http://www.us.debian.org/security/2006/dsa-1200http://www.vupen.com/english/advisories/2006/4099https://issues.rpath.com/browse/RPL-723https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10218
2006-10-18
Published