Tuesday, October 5, 2010

qt-creator: vulnerability

Users of qt-creator please be advised of a vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
MDVSA-2010:193: [MDVSA-2010:193] qt-creator
Problem Description:



A vulnerability has been found in Qt Creator 2.0.0 and previous

versions. The vulnerability occurs because of an insecure manipulation

of a Unix environment variable by the qtcreator shell script. It

manifests by causing Qt or Qt Creator to attempt to load certain

library names from the current working directory (CVE-2010-3374).


Read more at www.criticalwatch.com
 

No comments:

Post a Comment