CVE-2014-0190
published 2014-05-08CVE-2014-0190: The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.96%
89.3th percentile
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| qt | qt | < 5.3.0 | 5.3.0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9r7x-qv26-9x2m: The GIF decoder in QtGui in Qt before 5
ghsa_unreviewed·2022-05-13
CVE-2014-0190 [MEDIUM] CWE-476 GHSA-9r7x-qv26-9x2m: The GIF decoder in QtGui in Qt before 5
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
OSV
qt4-x11, qtbase-opensource-src vulnerabilities
osv·2015-06-03·CVSS 4.3
CVE-2014-0190 [MEDIUM] qt4-x11, qtbase-opensource-src vulnerabilities
qt4-x11, qtbase-opensource-src vulnerabilities
Wolfgang Schenk discovered that Qt incorrectly handled certain malformed
GIF images. If a user or automated system were tricked into opening a
specially crafted GIF image, a remote attacker could use this issue to
cause Qt to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-0190)
Fabian Vogt discovered that Qt incorrectly handled certain malformed BMP
images. If a user or automated system were tricked into opening a specially
crafted BMP image, a remote attacker could use this issue to cause Qt to
crash, resulting in a denial of service. (CVE-2015-0295)
Richard Moore and Fabian Vogt discovered that Qt incorrectly handled
certain malformed BMP images. If a user or automated
OSV
CVE-2014-0190: The GIF decoder in QtGui in Qt before 5
osv·2014-05-08·CVSS 4.3
CVE-2014-0190 [MEDIUM] CVE-2014-0190: The GIF decoder in QtGui in Qt before 5
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
Ubuntu
Qt vulnerabilities
vendor_ubuntu·2015-06-03·CVSS 4.3
CVE-2014-0190 [MEDIUM] Qt vulnerabilities
Title: Qt vulnerabilities
Summary: Qt could be made to crash or run programs as your login if it opened a
specially crafted file.
Wolfgang Schenk discovered that Qt incorrectly handled certain malformed
GIF images. If a user or automated system were tricked into opening a
specially crafted GIF image, a remote attacker could use this issue to
cause Qt to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-0190)
Fabian Vogt discovered that Qt incorrectly handled certain malformed BMP
images. If a user or automated system were tricked into opening a specially
crafted BMP image, a remote attacker could use this issue to cause Qt to
crash, resulting in a denial of service. (CVE-2015-0295)
Richard Moore and Fabian Vogt discover
Red Hat
qt: NULL pointer dereference flaw in QGIFFormat::fillRect
vendor_redhat·2014-04-14·CVSS 4.3
CVE-2014-0190 [MEDIUM] CWE-476 qt: NULL pointer dereference flaw in QGIFFormat::fillRect
qt: NULL pointer dereference flaw in QGIFFormat::fillRect
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
Package: qt (Red Hat Enterprise Linux 5) - Will not fix
Package: qt4 (Red Hat Enterprise Linux 5) - Will not fix
Package: qt (Red Hat Enterprise Linux 6) - Will not fix
Package: qt3 (Red Hat Enterprise Linux 6) - Will not fix
Package: qt (Red Hat Enterprise Linux 7) - Will not fix
Package: qt3 (Red Hat Enterprise Linux 7) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0190 mingw-qt: qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
bugzilla·2014-04-30·CVSS 4.3
CVE-2014-0190 [MEDIUM] CVE-2014-0190 mingw-qt: qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
CVE-2014-0190 mingw-qt: qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue
Bugzilla
CVE-2014-0190 mingw-qt5-qtbase: qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
bugzilla·2014-04-30·CVSS 4.3
CVE-2014-0190 [MEDIUM] CVE-2014-0190 mingw-qt5-qtbase: qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
CVE-2014-0190 mingw-qt5-qtbase: qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: thi
Bugzilla
CVE-2014-0190 qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
bugzilla·2014-04-28·CVSS 4.3
CVE-2014-0190 [MEDIUM] CVE-2014-0190 qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
CVE-2014-0190 qt: NULL pointer dereference flaw in QGIFFormat::fillRect [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
Bugzilla
CVE-2014-0190 qt: NULL pointer dereference flaw in QGIFFormat::fillRect
bugzilla·2014-04-16·CVSS 4.3
CVE-2014-0190 [MEDIUM] CVE-2014-0190 qt: NULL pointer dereference flaw in QGIFFormat::fillRect
CVE-2014-0190 qt: NULL pointer dereference flaw in QGIFFormat::fillRect
A NULL pointer dereference flaw was found in QGIFFormat::fillRect. If an application using the qt-x11 libraries opened a malicious GIF file, it could cause the application to crash.
Upstream bug: https://bugs.kde.org/show_bug.cgi?id=333404
Discussion:
Public now. Upstream notification and fix:
http://lists.qt-project.org/pipermail/announce/2014-April/000045.html
---
Created qt tracking bugs for this issue:
Affects: fedora-all [bug 1091774]
---
Doesn't this also affect mingw-qt and mingw-qt5-qtbase?
---
Created mingw-qt tracking bugs for this issue:
Affects: fedora-all [bug 1092836]
---
Created mingw-qt5-qtbase tracking bugs for this issue:
Affects: fedora-all [bug 1092837]
---
(In reply to Yaakov (Cyg
http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134040.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134141.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/132395.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00068.htmlhttp://lists.qt-project.org/pipermail/announce/2014-April/000045.htmlhttp://www.securityfocus.com/bid/67087http://www.ubuntu.com/usn/USN-2626-1https://bugs.kde.org/show_bug.cgi?id=333404http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134040.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-June/134141.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-May/132395.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00068.htmlhttp://lists.qt-project.org/pipermail/announce/2014-April/000045.htmlhttp://www.securityfocus.com/bid/67087http://www.ubuntu.com/usn/USN-2626-1https://bugs.kde.org/show_bug.cgi?id=333404
2014-05-08
Published