CVE-2015-1860: Buffer Overflow
Published May 12, 2015
·Updated
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image.
Affected Software
12 affected components
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Digia Qt<=4.8.6
Qt QT=5.0.0
Qt QT=5.0.1
Qt QT=5.0.2
Qt QT=5.1.0
Qt QT=5.2.0
Qt QT=5.2.1
Qt QT=5.3.0
Qt QT=5.4.1
Remediation
Patch Available
Event History
May 12, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1860?
CVE-2015-1860 has a high severity rating due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2015-1860?
To fix CVE-2015-1860, update to the latest version of Qt, specifically any version above 4.8.7 or 5.4.2.
3
What software is affected by CVE-2015-1860?
CVE-2015-1860 affects several versions of Qt and Fedora operating systems, specifically Fedora 20, 21, and 22.
4
What type of vulnerability is CVE-2015-1860?
CVE-2015-1860 is classified as a buffer overflow vulnerability in the QtBase module.
5
Can CVE-2015-1860 be exploited remotely?
Yes, CVE-2015-1860 can be exploited remotely through crafted GIF images.