PT-2012-1131 · Qt Company+1 · Qt+1

Matthias Weckbecker

·

Published

2011-09-21

·

Updated

2021-06-16

·

CVE-2011-3194

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qt versions prior to 4.7.4
Description The issue is related to a buffer overflow in the TIFF reader, which can be triggered by a greyscale TIFF image with multiple samples per pixel, specifically via the TIFFTAG SAMPLESPERPIXEL tag. This can cause a denial of service (crash) and potentially allow the execution of arbitrary code. The vulnerability can be exploited remotely, potentially leading to a breach of confidentiality, integrity, and availability of protected information.
Recommendations For Qt versions prior to 4.7.4, update to version 4.7.4 or later to resolve the issue. As a temporary workaround, consider restricting the handling of TIFF images with multiple samples per pixel to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09658
CVE-2011-3194
DLA-117-1
RHSA-2011:1323
RHSA-2011:1328
RHSA-2011_1323
RHSA-2011_1328

Affected Products

Qt
Red Hat