First published: Sat Jun 16 2012(Updated: )
Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the TIFFTAG_SAMPLESPERPIXEL tag in a greyscale TIFF image with multiple samples per pixel.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qt | =4.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3194 is considered a critical vulnerability that can lead to denial of service and potential arbitrary code execution.
To fix CVE-2011-3194, update to a version of Qt that is later than 4.7.4.
CVE-2011-3194 can be exploited by crafting a malicious greyscale TIFF image with multiple samples per pixel.
Yes, there are known exploits that utilize specially crafted TIFF images to trigger the vulnerability in CVE-2011-3194.
CVE-2011-3194 affects Qt version 4.7.4 specifically.