MGASA-2021-0262 - Updated qt4 and qtsvg5 packages fix a security vulnerability

Publication date: 16 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0262.html
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-3481

An out of bounds read in function QRadialFetchSimd from crafted svg file may
lead to information disclosure or other potential consequences. This update
includes the backported upstream fix and should resolve the security issue 
(CVE-2021-3481).

References:
- https://bugs.mageia.org/show_bug.cgi?id=29014
- https://bugreports.qt.io/browse/QTBUG-91507
- https://lists.fedoraproject.org/archives/list/[email protected]/thread/O57HZYEVZNCW5L74PDD7K44E7XZEBXRK/
- https://lists.fedoraproject.org/archives/list/[email protected]/thread/GOBQ75US43TETW2OID6APHQRENDFK4BO/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3481

SRPMS:
- 8/core/qt4-4.8.7-35.1.mga8
- 8/core/qtsvg5-5.15.2-1.1.mga8
- 7/core/qt4-4.8.7-26.3.mga7
- 7/core/qtsvg5-5.12.6-1.1.mga7