Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2014-0190

Published: 8 May 2014

The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.

Priority

Low

Status

Package Release Status
qt4-x11
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life)
precise
Released (4:4.8.1-0ubuntu4.9)
quantal Ignored
(reached end-of-life)
saucy Ignored
(reached end-of-life)
trusty
Released (4:4.8.5+git192-g085f851+dfsg-2ubuntu4.1)
upstream
Released (4:4.8.6+dfsg-1)
utopic Not vulnerable
(4:4.8.6+git49-gbc62005+dfsg-1ubuntu1)
vivid Not vulnerable
(4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu6)
Patches:
upstream: https://qt.gitorious.org/qt/qtbase/commit/eb1325047f2697d24e93ebaf924900affc876bc1

qtbase-opensource-src
Launchpad, Ubuntu, Debian
lucid Does not exist

precise Does not exist

quantal Does not exist

saucy Ignored
(reached end-of-life)
trusty Does not exist
(trusty was released [5.2.1+dfsg-1ubuntu14.3])
upstream
Released (5.3)
utopic Not vulnerable
(5.3.0+dfsg-2ubuntu9)
vivid Not vulnerable
(5.4.1+dfsg-2ubuntu3)
Patches:

upstream: http://code.qt.io/cgit/qt/qtbase.git/commit/?id=c5eec579e2fcf3c00cc02ebc0a2fbc347cd595d5