Unrated severityNVD Advisory· Published Aug 12, 2021· Updated Aug 4, 2024
CVE-2021-38593
CVE-2021-38593
Description
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
Affected products
11- Qt/Qtdescription
- osv-coords10 versionspkg:rpm/almalinux/qt5-qtbasepkg:rpm/almalinux/qt5-qtbase-commonpkg:rpm/almalinux/qt5-qtbase-develpkg:rpm/almalinux/qt5-qtbase-examplespkg:rpm/almalinux/qt5-qtbase-guipkg:rpm/almalinux/qt5-qtbase-mysqlpkg:rpm/almalinux/qt5-qtbase-odbcpkg:rpm/almalinux/qt5-qtbase-postgresqlpkg:rpm/almalinux/qt5-qtbase-private-develpkg:rpm/almalinux/qt5-qtbase-static
< 5.15.2-4.el8+ 9 more
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
- (no CPE)range: < 5.15.2-4.el8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36VN2WKMNQUSTF6ZW2X52NPAJVXJ4S5I/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HY5YCSDCTLHVMP3OXOM6HNTWHV6DBHDX/mitrevendor-advisory
- security.gentoo.org/glsa/202402-03mitrevendor-advisory
- bugs.chromium.org/p/oss-fuzz/issues/detailmitre
- github.com/google/oss-fuzz-vulns/blob/main/vulns/qt/OSV-2021-903.yamlmitre
- github.com/qt/qtbase/commit/1ca02cf2879a5e1511a2f2109f0925cf4c892862mitre
- github.com/qt/qtbase/commit/202143ba41f6ac574f1858214ed8bf4a38b73ccdmitre
- github.com/qt/qtbase/commit/6b400e3147dcfd8cc3a393ace1bd118c93762e0cmitre
- wiki.qt.io/Qt_5.15_Releasemitre
- www.qt.io/blog/qt-5.15-extended-support-for-subscription-license-holdersmitre
News mentions
0No linked articles in our index yet.