CVE-2015-0295
Not scored
CVE-2015-0295
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
Exploit probability
6.3%
Published
March 25, 2015
Required by
Not available
Last source change
April 16, 2026
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2015-0295
View original source
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
05 / REFERENCES
Further evidence
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/150800.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/150940.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151034.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151121.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151138.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/151352.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00068.html
- http://lists.qt-project.org/pipermail/announce/2015-February/000059.html
- http://www.securityfocus.com/bid/73029
- http://www.ubuntu.com/usn/USN-2626-1