FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-11-19 19:12:13 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
5713bfda-e27d-11e4-b2ce-5453ed2e2b49qt4-imageformats, qt4-gui, qt5-gui -- Multiple Vulnerabilities in Qt Image Format Handling

Richard J. Moore reports:

Due to two recent vulnerabilities identified in the built-in image format handling code, it was decided that this area required further testing to determine if further issues remained. Fuzzing using afl-fuzz located a number of issues in the handling of BMP, ICO and GIF files. The issues exposed included denial of service and buffer overflows leading to heap corruption. It is possible the latter could be used to perform remote code execution.


Discovery 2015-04-12
Entry 2015-04-14
qt4-imageformats
< 4.8.6_3

qt4-gui
< 4.8.6_5

qt5-gui
< 5.4.1_1

http://lists.qt-project.org/pipermail/announce/2015-April/000067.html
CVE-2015-1858
CVE-2015-1859
CVE-2015-1860
c9c3374d-c2c1-11e4-b236-5453ed2e2b49qt4-gui, qt5-gui -- DoS vulnerability in the BMP image handler

Richard J. Moore reports:

The builtin BMP decoder in QtGui prior to Qt 5.5 contained a bug that would lead to a division by zero when loading certain corrupt BMP files. This in turn would cause the application loading these hand crafted BMPs to crash.


Discovery 2015-02-22
Entry 2015-03-05
qt4-gui
< 4.8.6_4

qt5-gui
< 5.3.2_2

CVE-2015-0295
http://lists.qt-project.org/pipermail/announce/2015-February/000059.html