MGASA-2021-0262 - Updated qt4 and qtsvg5 packages fix a security vulnerability

Publication date: 16 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0262.html
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-3481

An out of bounds read in function QRadialFetchSimd from crafted svg file may
lead to information disclosure or other potential consequences. This update
includes the backported upstream fix and should resolve the security issue 
(CVE-2021-3481).

References:
- https://bugs.mageia.org/show_bug.cgi?id=29014
- https://bugreports.qt.io/browse/QTBUG-91507
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O57HZYEVZNCW5L74PDD7K44E7XZEBXRK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GOBQ75US43TETW2OID6APHQRENDFK4BO/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3481

SRPMS:
- 8/core/qt4-4.8.7-35.1.mga8
- 8/core/qtsvg5-5.15.2-1.1.mga8
- 7/core/qt4-4.8.7-26.3.mga7
- 7/core/qtsvg5-5.12.6-1.1.mga7

Mageia 2021-0262: qt4 and qtsvg5 security update

An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences

Summary

An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue (CVE-2021-3481).

References

- https://bugs.mageia.org/show_bug.cgi?id=29014

- https://bugreports.qt.io/browse/QTBUG-91507

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O57HZYEVZNCW5L74PDD7K44E7XZEBXRK/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GOBQ75US43TETW2OID6APHQRENDFK4BO/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3481

Resolution

MGASA-2021-0262 - Updated qt4 and qtsvg5 packages fix a security vulnerability

SRPMS

- 8/core/qt4-4.8.7-35.1.mga8

- 8/core/qtsvg5-5.15.2-1.1.mga8

- 7/core/qt4-4.8.7-26.3.mga7

- 7/core/qtsvg5-5.12.6-1.1.mga7

Severity
Publication date: 16 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0262.html
Type: security
CVE: CVE-2021-3481

Related News