Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38593

Опубликовано: 27 июл. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

A vulnerability was found in Qt, where an out-of-bounds write in the QOutlineMapper::convertPath function can lead to a denial of service, a remote attacker could exploit this flaw by sending a specially crafted request, causing the application to crash.

Отчет

This vulnerability is rated as moderate because it allows a remote attacker to trigger a denial of service through an out-of-bounds write, exploiting this flaw could crash the application, impacting availability but not compromising system security or integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qtOut of support scope
Red Hat Enterprise Linux 6qt3Not affected
Red Hat Enterprise Linux 7qtOut of support scope
Red Hat Enterprise Linux 7qt3Not affected
Red Hat Enterprise Linux 7qt5-qtbaseOut of support scope
Red Hat Enterprise Linux 8qt5Affected
Red Hat Enterprise Linux 9qt5Affected
Red Hat Enterprise Linux 9qt5-qtbaseNot affected
Red Hat Enterprise Linux 8qt5-qtbaseFixedRHSA-2022:179610.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1994719qt: out-of-bounds write in QOutlineMapper::convertPath called from QRasterPaintEngine::fill and QPaintEngineEx::stroke

EPSS

Процентиль: 75%
0.00834
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

CVSS3: 7.5
nvd
больше 4 лет назад

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

CVSS3: 7.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write ...

rocky
почти 4 года назад

Moderate: qt5-qtbase security update

EPSS

Процентиль: 75%
0.00834
Низкий

7.5 High

CVSS3