Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38593

Опубликовано: 27 июл. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

Отчет

This vulnerability is rated as moderate because it allows a remote attacker to trigger a denial of service through an out-of-bounds write, exploiting this flaw could crash the application, impacting availability but not compromising system security or integrity. Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-787: Out-of-bounds Write vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. The platform enforces hardening guidelines to apply the most restrictive settings necessary for operational requirements. Baseline configurations and system controls ensure secure software settings, while least functionality reduces the attack surface by disabling unauthorized services and ports. The environment employs IPS/IDS and antimalware solutions to detect and prevent malicious code exploiting out-of-bounds write vulnerabilities, using mechanisms such as file integrity monitoring and patch management. Robust input validation and error handling ensure all user inputs are thoroughly validated, preventing instability, data exposure, or privilege escalation. Finally, the platform uses memory protection mechanisms such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) to strengthen resilience against out-of-bounds write exploits.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qtOut of support scope
Red Hat Enterprise Linux 6qt3Not affected
Red Hat Enterprise Linux 7qtOut of support scope
Red Hat Enterprise Linux 7qt3Not affected
Red Hat Enterprise Linux 7qt5-qtbaseOut of support scope
Red Hat Enterprise Linux 8qt5Affected
Red Hat Enterprise Linux 9qt5Affected
Red Hat Enterprise Linux 9qt5-qtbaseNot affected
Red Hat Enterprise Linux 8qt5-qtbaseFixedRHSA-2022:179610.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1994719qt: out-of-bounds write in QOutlineMapper::convertPath called from QRasterPaintEngine::fill and QPaintEngineEx::stroke

EPSS

Процентиль: 74%
0.00836
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

CVSS3: 7.5
nvd
почти 4 года назад

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 4 года назад

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write ...

rocky
около 3 лет назад

Moderate: qt5-qtbase security update

EPSS

Процентиль: 74%
0.00836
Низкий

7.5 High

CVSS3