The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Qt | Qt | * | 5.3.0 (excluding) |
| Qt4-x11 | Ubuntu | esm-infra-legacy/trusty | * |
| Qt4-x11 | Ubuntu | lucid | * |
| Qt4-x11 | Ubuntu | precise | * |
| Qt4-x11 | Ubuntu | quantal | * |
| Qt4-x11 | Ubuntu | saucy | * |
| Qt4-x11 | Ubuntu | trusty | * |
| Qt4-x11 | Ubuntu | trusty/esm | * |
| Qt4-x11 | Ubuntu | upstream | * |
| Qtbase-opensource-src | Ubuntu | saucy | * |
| Qtbase-opensource-src | Ubuntu | trusty | * |
| Qtbase-opensource-src | Ubuntu | upstream | * |
| Qtbase-opensource-src | Ubuntu | vivid/stable-phone-overlay | * |