QT Assistant leaves port unfiltered

From: Rohit Sharma (rohits79at_private)
Date: Sun Sep 29 2002 - 05:56:13 PDT

  • Next message: Brian E: "Re: Postnuke XSS issues [correction]"

    
     ('binary' encoding is not supported, stored as-is)
    QT Assistant (http://www.trolltech.com) opens an
    unfiltered port (#7358) when it is executed from the QT
    Designer program.
    
    It is possible to open any local html page within the
    QT Assistant program from any remote machine
    
    The entire explanation is as it posted to the BUG@Trolltech
    http://lists.trolltech.com/qt-interest/2002-09/thread00549-0.html
    
    Block any incoming connections to tcp port 7358 if you
    are using QTDesigner +Assistant 
    
    Rohit
    Sorry for poor english!
    
    
    Return mail from the vendor regarding the bug
    ___________________________________
    
    Hi,
    
    > [...]
    > Problem::
    > For any happy developer reading the documentation
    through Assistant it
    > is possible
    >
    > (1) That a remote user open any local html page
    (provided they have
    > the permission to read html) on the Assistant
    program. The assistant
    > program will not load any remote web pages but only
    those available on
    > the local machine.
    
    This problem was addressed in Qt 3.1 and it should be
    fixed there. In
    Qt 3.0 it was not meant to be like that anymore and the
    problem that the
    port was still open is rather a mistake which should be
    fixed now for
    upcomin
    g Qt 3.0 releases.
    
    Thank you for informing us about this problem.
    
    Best regards, Rainer
    
    - --
    Rainer M. Schmid
    Trolltech AS, Waldemar Thranes gate 98, NO-0175 Oslo,
    Norway
    



    This archive was generated by hypermail 2b30 : Mon Sep 30 2002 - 15:02:52 PDT