CVE Vulnerabilities

CVE-2015-0295

Published: Mar 25, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.

Affected Software

NameVendorStart VersionEnd Version
FedoraFedoraproject20 (including)20 (including)
FedoraFedoraproject21 (including)21 (including)
FedoraFedoraproject22 (including)22 (including)
Qt4-x11Ubuntudevel*
Qt4-x11Ubuntuesm-infra-legacy/trusty*
Qt4-x11Ubuntulucid*
Qt4-x11Ubuntuprecise*
Qt4-x11Ubuntutrusty*
Qt4-x11Ubuntutrusty/esm*
Qt4-x11Ubuntuutopic*
Qt4-x11Ubuntuvivid*
Qtbase-opensource-srcUbuntutrusty*
Qtbase-opensource-srcUbuntuupstream*
Qtbase-opensource-srcUbuntuutopic*
Qtbase-opensource-srcUbuntuvivid/stable-phone-overlay*

References