7.1

CVE-2021-3481

Exploit
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qt ≫ Qt Version 5.15.1
Qt ≫ Qt Version 6.0.0 Update -
Qt ≫ Qt Version 6.0.2
Qt ≫ Qt Version 6.2.0 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.433
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html
https://access.redhat.com/security/cve/CVE-2021-3481
Third Party Advisory
https://bugreports.qt.io/browse/QTBUG-91507
Vendor Advisory
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=1931444
Third Party Advisory
Issue Tracking
https://codereview.qt-project.org/c/qt/qtsvg/+/337646
Vendor Advisory