Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-45930

Опубликовано: 31 дек. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOpsQPainterPath::Element::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

A flaw was found in qtsvg's qsvghandler.cpp module. An attacker who is able to submit a crafted image file to an application that uses qsvghandler could cause an out-of-bounds write and potential denial of service to occur, depending on the application.

Отчет

This flaw is out of support scope for versions of qt shipped with Red Hat Enterprise Linux 6 and 7 as it does not affect qt3, which does not have the qsvghandler.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qtOut of support scope
Red Hat Enterprise Linux 6qt3Not affected
Red Hat Enterprise Linux 7qtOut of support scope
Red Hat Enterprise Linux 7qt3Not affected
Red Hat Enterprise Linux 7qt5-qtsvgOut of support scope
Red Hat Enterprise Linux 9qt5-qtsvgNot affected
Red Hat Enterprise Linux 8qt5-qtsvgFixedRHSA-2022:192010.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2037339qt: out-of-bounds write may lead to DoS

EPSS

Процентиль: 25%
0.00081
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

CVSS3: 5.5
nvd
больше 3 лет назад

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

CVSS3: 5.5
debian
больше 3 лет назад

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-o ...

rocky
около 3 лет назад

Moderate: qt5-qtsvg security update

CVSS3: 5.5
github
больше 3 лет назад

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

EPSS

Процентиль: 25%
0.00081
Низкий

7.5 High

CVSS3