5
CVSSv2

CVE-2015-0295

Published: 25/03/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The BMP decoder in QtGui in QT prior to 5.5 does not properly calculate the masks used to extract the color components, which allows remote malicious users to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 20

fedoraproject fedora 21

fedoraproject fedora 22

opensuse opensuse 13.1

digia qt

Vendor Advisories

Qt could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #779550 qt4-x11: CVE-2015-0295 Package: qt4-x11; Maintainer for qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 2 Mar 2015 07:06:02 UTC Severity: grave Tags: security Fixed in versions qt4-x11/4:486+git64-g ...
Debian Bug report logs - #783133 qt4-x11: CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 Package: src:qt4-x11; Maintainer for src:qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 22 Apr 2015 18:18:02 UTC Severity: normal Tags: fixed-ups ...
The BMP decoder in QtGui in QT before 55 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file ...