CVE-2021-3481
Summary
| CVE | CVE-2021-3481 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-22 15:15:00 UTC |
| Updated | 2023-08-23 01:15:00 UTC |
| Description | A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| [SECURITY] [DLA 3539-1] qt4-x11 security update | MLIST | lists.debian.org | |
| codereview.qt-project.org/c/qt/qtsvg/+/337646 | MISC | codereview.qt-project.org | |
| [QTBUG-91507] Out of bounds read in function `QRadialFetchSimd<QSimdSse2>::fetch` when input craft svg file - Qt Bug Tracker | MISC | bugreports.qt.io | |
| 1931444 – (CVE-2021-3481) CVE-2021-3481 qt: Out of bounds read in function QRadialFetchSimd from crafted svg file | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179021 Debian Security Update for qtsvg-opensource-src (DLA 2885-1)
- 179027 Debian Security Update for qt4-x11 (DLA 2895-1)
- 179898 Debian Security Update for qtsvg-opensource-src (CVE-2021-3481)
- 198637 Ubuntu Security Notification for QtSvg Vulnerabilities (USN-5241-1)
- 239804 Red Hat Update for qt5 security (RHSA-2021:4172)
- 6000048 Debian Security Update for qt4-x11 (DLA 3539-1)
- 751207 SUSE Enterprise Linux Security Update for libqt5-qtsvg (SUSE-SU-2021:3333-1)
- 751218 OpenSUSE Security Update for libqt5-qtsvg (openSUSE-SU-2021:3354-1)
- 751240 OpenSUSE Security Update for libqt5-qtsvg (openSUSE-SU-2021:1371-1)
- 751541 SUSE Enterprise Linux Security Update for libqt4 (SUSE-SU-2021:4155-1)
- 940024 AlmaLinux Security Update for qt5 (ALSA-2021:4172)
- 960197 Rocky Linux Security Update for qt5 (RLSA-2021:4172)