First published: Mon Feb 22 2021(Updated: )
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/qt | <5.12.11 | 5.12.11 |
redhat/qt | <5.15.4 | 5.15.4 |
redhat/qt | <6.0.3 | 6.0.3 |
redhat/qt | <6.1.0 | 6.1.0 |
Qt Qt | =5.15.1 | |
Qt Qt | =6.0.0 | |
Qt Qt | =6.0.2 | |
Qt Qt | =6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3481 is a vulnerability found in Qt, specifically in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h.
The severity of CVE-2021-3481 is high with a CVSS score of 7.1.
CVE-2021-3481 occurs due to an out-of-bounds read vulnerability while rendering and displaying a crafted SVG file.
Versions 5.15.1, 6.0.0, 6.0.2, and 6.2.0 of Qt are affected by CVE-2021-3481.
To fix CVE-2021-3481, update to version 5.12.11 or later for Qt 5 or version 6.0.3 or later for Qt 6.