Mageia 2021-0262: qt4 and qtsvg5 security update
Summary
An out of bounds read in function QRadialFetchSimd from crafted svg file may
lead to information disclosure or other potential consequences. This update
includes the backported upstream fix and should resolve the security issue
(CVE-2021-3481).
References
- https://bugs.mageia.org/show_bug.cgi?id=29014
- https://bugreports.qt.io/browse/QTBUG-91507
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/O57HZYEVZNCW5L74PDD7K44E7XZEBXRK/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GOBQ75US43TETW2OID6APHQRENDFK4BO/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3481
Resolution
MGASA-2021-0262 - Updated qt4 and qtsvg5 packages fix a security vulnerability
SRPMS
- 8/core/qt4-4.8.7-35.1.mga8
- 8/core/qtsvg5-5.15.2-1.1.mga8
- 7/core/qt4-4.8.7-26.3.mga7
- 7/core/qtsvg5-5.12.6-1.1.mga7