First published: Tue May 12 2015(Updated: )
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qt | <=4.8.6 | |
Trolltech Qt | =5.0.0 | |
Trolltech Qt | =5.0.1 | |
Trolltech Qt | =5.0.2 | |
Trolltech Qt | =5.1.0 | |
Trolltech Qt | =5.2.0 | |
Trolltech Qt | =5.2.1 | |
Trolltech Qt | =5.3.0 | |
Trolltech Qt | =5.4.1 | |
Fedora | =20 | |
Fedora | =21 | |
Fedora | =22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1858 has a high severity due to the potential for denial of service and arbitrary code execution.
To fix CVE-2015-1858, update your QtBase module to version 4.8.7 or later, or 5.4.2 or later.
CVE-2015-1858 affects Qt versions prior to 4.8.7 and 5.x before 5.4.2.
Yes, attackers can exploit CVE-2015-1858 by sending crafted BMP images to trigger buffer overflows.
CVE-2015-1858 can cause segmentation faults and crashes, leading to a denial of service on the affected systems.