6.8
CVSSv2

CVE-2015-1859

Published: 12/05/2015 Updated: 16/06/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt prior to 4.8.7 and 5.x prior to 5.4.2 allow remote malicious users to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 22

fedoraproject fedora 20

fedoraproject fedora 21

digia qt

qt qt 5.0.0

qt qt 5.4.1

qt qt 5.2.1

qt qt 5.3.0

qt qt 5.1.0

qt qt 5.2.0

qt qt 5.0.1

qt qt 5.0.2

Vendor Advisories

Qt could be made to crash or run programs as your login if it opened a specially crafted file ...
Debian Bug report logs - #779550 qt4-x11: CVE-2015-0295 Package: qt4-x11; Maintainer for qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 2 Mar 2015 07:06:02 UTC Severity: grave Tags: security Fixed in versions qt4-x11/4:486+git64-g ...
Debian Bug report logs - #783133 qt4-x11: CVE-2015-1858 CVE-2015-1859 CVE-2015-1860 Package: src:qt4-x11; Maintainer for src:qt4-x11 is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 22 Apr 2015 18:18:02 UTC Severity: normal Tags: fixed-ups ...
A memory corruption flaw was found in the way Qt handled certain Icon (ICO) files If a user loaded a specially crafted ICO image file with an application linked against Qt, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application ...