CVE-2015-0295
Publication date 25 March 2015
Last updated 24 July 2024
Ubuntu priority
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
Status
Package | Ubuntu Release | Status |
---|---|---|
qt4-x11 | ||
14.04 LTS trusty |
Fixed 4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1
|
|
qtbase-opensource-src | ||
14.04 LTS trusty |
Fixed 5.2.1+dfsg-1ubuntu14.3
|
|
Notes
mdeslaur
debian released 4:4.8.6+git64-g5dc8b2b+dfsg-3 with this fix, but ubuntu's package was based on an unreleased snapshot and didn't include the patch.
Patch details
Package | Patch details |
---|---|
qt4-x11 |
|
qtbase-opensource-src |
|
References
Related Ubuntu Security Notices (USN)
- USN-2626-1
- Qt vulnerabilities
- 3 June 2015