The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fedora | Fedoraproject | 20 (including) | 20 (including) |
Fedora | Fedoraproject | 21 (including) | 21 (including) |
Fedora | Fedoraproject | 22 (including) | 22 (including) |
Qt4-x11 | Ubuntu | devel | * |
Qt4-x11 | Ubuntu | lucid | * |
Qt4-x11 | Ubuntu | precise | * |
Qt4-x11 | Ubuntu | trusty | * |
Qt4-x11 | Ubuntu | utopic | * |
Qt4-x11 | Ubuntu | vivid | * |
Qtbase-opensource-src | Ubuntu | trusty | * |
Qtbase-opensource-src | Ubuntu | upstream | * |
Qtbase-opensource-src | Ubuntu | utopic | * |
Qtbase-opensource-src | Ubuntu | vivid/stable-phone-overlay | * |