Advisories ยป MGASA-2015-0105

Updated qt3, qt4 and qtbase5 packages fix security vulnerability

Publication date: 12 Mar 2015
Modification date: 12 Mar 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2015-0295

Description

The builtin BMP decoder in QtGui prior to Qt 5.5 contained a bug that would
lead to a divsion by zero when loading certain corrupt BMP files (CVE-2015-0295).
This in turn would cause the application loading these hand crafted BMPs to crash.
Qt3, Qt4 and qtbase5 have been patched to prevent this division by zero.
                

References

SRPMS

4/core