CVE-2015-1858: Buffer Overflow
Published May 12, 2015
·Updated
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image.
Affected Software
12 affected components
Digia Qt<=4.8.6
Qt QT=5.0.0
Qt QT=5.0.1
Qt QT=5.0.2
Qt QT=5.1.0
Qt QT=5.2.0
Qt QT=5.2.1
Qt QT=5.3.0
Qt QT=5.4.1
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Remediation
Patch Available
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1858?
CVE-2015-1858 has a high severity due to the potential for denial of service and arbitrary code execution.
2
How do I fix CVE-2015-1858?
To fix CVE-2015-1858, update your QtBase module to version 4.8.7 or later, or 5.4.2 or later.
3
What versions of Qt are affected by CVE-2015-1858?
CVE-2015-1858 affects Qt versions prior to 4.8.7 and 5.x before 5.4.2.
4
Can attackers exploit CVE-2015-1858 through BMP images?
Yes, attackers can exploit CVE-2015-1858 by sending crafted BMP images to trigger buffer overflows.
5
What impact does CVE-2015-1858 have on systems?
CVE-2015-1858 can cause segmentation faults and crashes, leading to a denial of service on the affected systems.