CVE-2021-3481
published 2022-08-22CVE-2021-3481: A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While…
PriorityP429high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.51%
40.2th percentile
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qtsvg-opensource-src | < qtsvg-opensource-src 5.15.2-3 (bookworm) | qtsvg-opensource-src 5.15.2-3 (bookworm) |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| qt | qt | — | — |
| ubuntu | qtsvg-opensource-src | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QtSvg vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 6.5
CVE-2023-32573 [MEDIUM] QtSvg vulnerabilities
Title: QtSvg vulnerabilities
Summary: Several security issues were fixed in QtSvg.
It was discovered that QtSvg incorrectly handled certain SVG images. An
attacker could possibly use this issue to cause QtSvg to crash, resulting in
a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-19869)
It was discovered that QtSvg incorrectly handled certain SVG images. An
attacker could use this issue to cause QtSvg to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-3481,
CVE-2021-28025, CVE-2021-45930)
It was discovered that QtSvg incorrectly handled certain SVG images. An
attacker could use this issue to cause QtSvg to crash, resulting in a
denial of service, or possibly e
Ubuntu
QtSvg vulnerabilities
vendor_ubuntu·2022-01-19
CVE-2018-19869 QtSvg vulnerabilities
Title: QtSvg vulnerabilities
Summary: Several security issues were fixed in QtSvg.
It was discovered that QtSvg incorrectly handled certain malformed SVG
images. If a user or automated system were tricked into opening a specially
crafted image file, a remote attacker could use this issue to cause QtSvg
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
qt: Out of bounds read in function QRadialFetchSimd from crafted svg file
vendor_redhat·2021-02-22·CVSS 7.1
CVE-2021-3481 [HIGH] CWE-125 qt: Out of bounds read in function QRadialFetchSimd from crafted svg file
qt: Out of bounds read in function QRadialFetchSimd from crafted svg file
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confid
Debian
CVE-2021-3481: qtsvg-opensource-src - A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadial...
vendor_debian·2021·CVSS 7.1
CVE-2021-3481 [HIGH] CVE-2021-3481: qtsvg-opensource-src - A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadial...
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
Scope: local
bookworm: resolved (fixed in 5.15.2-3)
bullseye: resolved (fixed in 5.15.2-3)
forky: resolved (fixed in 5.15.2-3)
sid: resolved (fixed in 5.15.2-3)
trixie: resolved (fixed in 5.15.2-3)
GHSA
GHSA-jgc8-vf4g-2f67: A flaw was found in Qt
ghsa_unreviewed·2022-08-23
CVE-2021-3481 [HIGH] CWE-125 GHSA-jgc8-vf4g-2f67: A flaw was found in Qt
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
OSV
CVE-2021-3481: A flaw was found in Qt
osv·2022-08-22·CVSS 7.1
CVE-2021-3481 [HIGH] CVE-2021-3481: A flaw was found in Qt
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3481https://bugreports.qt.io/browse/QTBUG-91507https://bugzilla.redhat.com/show_bug.cgi?id=1931444https://codereview.qt-project.org/c/qt/qtsvg/+/337646https://lists.debian.org/debian-lts-announce/2023/08/msg00028.htmlhttps://access.redhat.com/security/cve/CVE-2021-3481https://bugreports.qt.io/browse/QTBUG-91507https://bugzilla.redhat.com/show_bug.cgi?id=1931444https://codereview.qt-project.org/c/qt/qtsvg/+/337646https://lists.debian.org/debian-lts-announce/2023/08/msg00028.html
2022-08-22
Published