Bugtraq mailing list archives

QT Assistant leaves port unfiltered


From: Rohit Sharma <rohits79 () yahoo com>
Date: 29 Sep 2002 12:56:13 -0000




QT Assistant (http://www.trolltech.com) opens an
unfiltered port (#7358) when it is executed from the QT
Designer program.

It is possible to open any local html page within the
QT Assistant program from any remote machine

The entire explanation is as it posted to the BUG@Trolltech
http://lists.trolltech.com/qt-interest/2002-09/thread00549-0.html

Block any incoming connections to tcp port 7358 if you
are using QTDesigner +Assistant 

Rohit
Sorry for poor english!


Return mail from the vendor regarding the bug
___________________________________

Hi,

[...]
Problem::
For any happy developer reading the documentation
through Assistant it
is possible

(1) That a remote user open any local html page
(provided they have
the permission to read html) on the Assistant
program. The assistant
program will not load any remote web pages but only
those available on
the local machine.

This problem was addressed in Qt 3.1 and it should be
fixed there. In
Qt 3.0 it was not meant to be like that anymore and the
problem that the
port was still open is rather a mistake which should be
fixed now for
upcomin
g Qt 3.0 releases.

Thank you for informing us about this problem.

Best regards, Rainer

- --
Rainer M. Schmid
Trolltech AS, Waldemar Thranes gate 98, NO-0175 Oslo,
Norway


Current thread: