Summary
The remote host is missing an update to qt
announced via advisory FEDORA-2009-8800.
Solution
Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update qt' at the command line.
For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
https://secure1.securityspace.com/smysecure/catid.html?in=FEDORA-2009-8800
Insight
Update Information:
Qt's WebKit code did not properly handle numeric character references, which could allow remote attackers to cause a denial of service (memory corruption and application crash) via a crafted HTML document.
Also included is:
* a fix for lib symlinks changing erroneously on upgrades * a fix for Copy and paste issues
* added support for more x keycodes
ChangeLog:
* Tue Aug 18 2009 Than Ngo - 4.5.2-2
- security fix for CVE-2009-1725
* Tue Aug 18 2009 Rex Dieter 4.5.2-1.2
- kde-qt: 287-qmenu-respect-minwidth
- kde-qt: 0288-more-x-keycodes (#475247)
* Wed Aug 5 2009 Rex Dieter 4.5.2-1.1
- use linker scripts for _debug targets (#510246)
- apply upstream patch to fix issue in Copy and paste - optimize (icon-mostly) scriptlets
- -x11: Requires(post,postun): /sbin/ldconfig
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-1725 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities