FS#70262 - [qt5-svg] [Security] information disclosure (CVE-2021-3481)
Attached to Project:
Arch Linux
Opened by Jonas Witschel (diabonas) - Friday, 02 April 2021, 13:31 GMT
Last edited by Antonio Rojas (arojas) - Friday, 02 April 2021, 18:02 GMT
Opened by Jonas Witschel (diabonas) - Friday, 02 April 2021, 13:31 GMT
Last edited by Antonio Rojas (arojas) - Friday, 02 April 2021, 18:02 GMT
|
Details
Summary
======= The package qt5-svg is vulnerable to information disclosure and denial of service via CVE-2021-3481. Guidance ======== Applying commit 9311a42677db244cd1c584f27270fa73f69d90d7 referenced below fixes the issue. References ========== https://security.archlinux.org/AVG-1769 https://bugzilla.redhat.com/show_bug.cgi?id=1931444 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=31668 https://bugreports.qt.io/browse/QTBUG-91507 https://codereview.qt-project.org/c/qt/qtsvg/+/337587 https://codereview.qt-project.org/gitweb?p=qt/qtsvg.git;a=commitdiff;h=9311a42677db244cd1c584f27270fa73f69d90d7 |
This task depends upon
Closed by Antonio Rojas (arojas)
Friday, 02 April 2021, 18:02 GMT
Reason for closing: Fixed
Additional comments about closing: qt5-svg 5.15.2-2
Friday, 02 April 2021, 18:02 GMT
Reason for closing: Fixed
Additional comments about closing: qt5-svg 5.15.2-2