CVE-2015-1859: Buffer Overflow
Published May 12, 2015
·Updated
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image.
Affected Software
12 affected components
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Digia Qt<=4.8.6
Qt QT=5.0.0
Qt QT=5.0.1
Qt QT=5.0.2
Qt QT=5.1.0
Qt QT=5.2.0
Qt QT=5.2.1
Qt QT=5.3.0
Qt QT=5.4.1
Remediation
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1859?
CVE-2015-1859 has a high severity due to the potential for denial of service and arbitrary code execution.
2
How can I fix CVE-2015-1859?
To fix CVE-2015-1859, upgrade to Qt 4.8.7 or 5.4.2 or later versions.
3
What causes the vulnerability in CVE-2015-1859?
The vulnerability in CVE-2015-1859 is caused by multiple buffer overflows in the ICO image handling of Qt.
4
Which versions of Qt are affected by CVE-2015-1859?
CVE-2015-1859 affects all Qt versions before 4.8.7 and 5.x versions before 5.4.2.
5
Can CVE-2015-1859 allow remote code execution?
Yes, CVE-2015-1859 can potentially allow remote attackers to execute arbitrary code via a crafted ICO image.