USN-829-1: Qt vulnerability
10 September 2009
Qt vulnerability
Releases
Packages
- qt4-x11 -
Details
It was discovered that Qt did not properly handle certificates with NULL
characters in the Subject Alternative Name field of X.509 certificates. An
attacker could exploit this to perform a machine-in-the-middle attack to view
sensitive information or alter encrypted communications. (CVE-2009-2700)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.04
Ubuntu 8.10
Ubuntu 8.04
After a standard system upgrade you need to restart your session to effect
the necessary changes.