First published: Wed Mar 25 2015(Updated: )
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fedoraproject Fedora | =20 | |
Fedoraproject Fedora | =21 | |
Fedoraproject Fedora | =22 | |
openSUSE | =13.1 | |
Qt | <=5.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0295 has a moderate severity level as it may lead to a denial of service condition.
To fix CVE-2015-0295, upgrade to a version of QT that is 5.5 or later.
CVE-2015-0295 affects QT versions up to and including 5.4.1, as well as specific versions of Fedora and openSUSE.
CVE-2015-0295 is a denial of service vulnerability resulting from improper handling of BMP files.
Yes, CVE-2015-0295 can be exploited remotely through crafted BMP files to crash the application.