Updated qt4 and qtsvg5 packages fix a security vulnerability
Publication date: 16 Jun 2021Modification date: 16 Jun 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-3481
Description
An out of bounds read in function QRadialFetchSimd from crafted svg file may lead to information disclosure or other potential consequences. This update includes the backported upstream fix and should resolve the security issue (CVE-2021-3481).
References
- https://bugs.mageia.org/show_bug.cgi?id=29014
- https://bugreports.qt.io/browse/QTBUG-91507
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O57HZYEVZNCW5L74PDD7K44E7XZEBXRK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GOBQ75US43TETW2OID6APHQRENDFK4BO/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3481
SRPMS
8/core
- qt4-4.8.7-35.1.mga8
- qtsvg5-5.15.2-1.1.mga8
7/core
- qt4-4.8.7-26.3.mga7
- qtsvg5-5.12.6-1.1.mga7