CVE-2021-45930Out-of-bounds Write in Qtsvg-opensource-src

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 1
Latest updateFeb 8

Description

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

debiandebian/qtsvg-opensource-src< qtsvg-opensource-src 5.15.2-4 (bookworm)
NVDqt/qtsvg5.0.05.15.2+1

Also affects: Debian Linux 9.0, Fedora 34, 35

Patches

🔴Vulnerability Details

2
GHSA
GHSA-66fw-grvj-p2h2: Qt SVG in Qt 52022-02-08
OSV
CVE-2021-45930: Qt SVG in Qt 52022-01-01

📋Vendor Advisories

3
Ubuntu
QtSvg vulnerabilities2022-01-19
Red Hat
qt: out-of-bounds write may lead to DoS2021-12-31
Debian
CVE-2021-45930: qtsvg-opensource-src - Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds w...2021
CVE-2021-45930 — Out-of-bounds Write | cvebase