DESCRIPTION
QT[1] is a cross-platform GUI toolkit mostly used by KDE.
Chris Evans found[2] a heap overflow vulnerability[3] in the QT
library when handling 8-bit RLE encoded BMP files. An attacker could
use this to compromise the account used to view the specially crafted
image. Further investigations found similar vulnerabilities in
XPM[4], GIF[5] and JPEG image handlers.
SOLUTION
It is recommended that all qt users upgrade their packages.
IMPORTANT: all applications linked against libqt must be restarted
after the upgrade in order to close the vulnerabilities.