MGASA-2021-0262
Dashboard / Vulnerabilities / MGASA-2021-0262
Summary: Updated qt4 and qtsvg5 packages fix a security vulnerability
Details: An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue (CVE-2021-3481).
References: https://advisories.mageia.org/MGASA-2021-0262.html, https://bugs.mageia.org/show_bug.cgi?id=29014, https://bugreports.qt.io/browse/QTBUG-91507, https://lists.fedoraproject.org/archives/list/[email protected]/thread/O57HZYEVZNCW5L74PDD7K44E7XZEBXRK/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/GOBQ75US43TETW2OID6APHQRENDFK4BO/
Affected packages
Package
Name: qt4
Purl: pkg:rpm/mageia/qt4?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
