CVE-2015-0295Divide By Zero in Qtbase-opensource-src

Severity
5.0MEDIUMNVD
OSV4.3
EPSS
3.6%
top 12.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25
Latest updateMay 14

Description

The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/qtbase-opensource-src< qtbase-opensource-src 5.3.2+dfsg-5 (bookworm)
NVDdigia/qt5.4.1

Also affects: Fedora 20, 21, 22

🔴Vulnerability Details

3
GHSA
GHSA-8p7m-hxqm-w38g: The BMP decoder in QtGui in QT before 52022-05-14
OSV
qt4-x11, qtbase-opensource-src vulnerabilities2015-06-03
OSV
CVE-2015-0295: The BMP decoder in QtGui in QT before 52015-03-25

📋Vendor Advisories

3
Ubuntu
Qt vulnerabilities2015-06-03
Red Hat
QT: BMP image handler crash2015-02-27
Debian
CVE-2015-0295: qtbase-opensource-src - The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks ...2015

💬Community

3
Bugzilla
CVE-2015-0295 QT: BMP image handler crash2015-02-28
Bugzilla
CVE-2015-0295 QT: BMP image handler crash [fedora-all]2015-02-28
Bugzilla
CVE-2015-0295 qt3: QT: BMP image handler crash [fedora-all]2015-02-28
CVE-2015-0295 — Divide By Zero in Qtbase-opensource-src | cvebase