CVE-2015-0295: Medium severity red hat fedora vulnerability
Published Mar 25, 2015
·Updated
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
Affected Software
5 affected components
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
openSUSE openSUSE=13.1
Digia Qt<=5.4.1
Event History
Mar 25, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0295?
CVE-2015-0295 has a moderate severity level as it may lead to a denial of service condition.
2
How do I fix CVE-2015-0295?
To fix CVE-2015-0295, upgrade to a version of QT that is 5.5 or later.
3
Which software is affected by CVE-2015-0295?
CVE-2015-0295 affects QT versions up to and including 5.4.1, as well as specific versions of Fedora and openSUSE.
4
What type of vulnerability is CVE-2015-0295?
CVE-2015-0295 is a denial of service vulnerability resulting from improper handling of BMP files.
5
Can I exploit CVE-2015-0295 remotely?
Yes, CVE-2015-0295 can be exploited remotely through crafted BMP files to crash the application.