A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2021-3481 | Third Party Advisory |
https://bugreports.qt.io/browse/QTBUG-91507 | Exploit Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1931444 | Issue Tracking Third Party Advisory |
https://codereview.qt-project.org/c/qt/qtsvg/+/337646 | Vendor Advisory |
https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html |
Configurations
Configuration 1 (hide)
|
History
25 Aug 2022, 00:42
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://bugreports.qt.io/browse/QTBUG-91507 - Exploit, Vendor Advisory | |
References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1931444 - Issue Tracking, Third Party Advisory | |
References | (MISC) https://access.redhat.com/security/cve/CVE-2021-3481 - Third Party Advisory | |
References | (MISC) https://codereview.qt-project.org/c/qt/qtsvg/+/337646 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.1 |
CWE | CWE-125 | |
CPE | cpe:2.3:a:qt:qt:6.0.2:*:*:*:*:*:*:* cpe:2.3:a:qt:qt:6.2.0:-:*:*:*:*:*:* cpe:2.3:a:qt:qt:6.0.0:-:*:*:*:*:*:* cpe:2.3:a:qt:qt:5.15.1:*:*:*:*:*:*:* |
22 Aug 2022, 16:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-22 15:15
Updated : 2024-02-04 22:51
NVD link : CVE-2021-3481
Mitre link : CVE-2021-3481
CVE.ORG link : CVE-2021-3481
JSON object : View
Products Affected
qt
- qt
CWE
CWE-125
Out-of-bounds Read