CVE-2021-28025

unknown
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2021-28025 NameCVE-2021-28025 DescriptionInteger Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS). SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages…

CVE-2021-28025

NameCVE-2021-28025
DescriptionInteger Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
qt6-svg (PTS)bookworm6.4.2-2fixed
trixie6.8.2-3fixed
forky6.10.2-7fixed
sid6.10.2-8fixed
qtsvg-opensource-src (PTS)bullseye5.15.2-3vulnerable
bookworm5.15.8-3fixed
trixie5.15.15-2fixed
forky, sid5.15.17-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
qt4-x11source(unstable)(unfixed)
qt6-svgsource(unstable)(not affected)
qtsvg-opensource-srcsource(unstable)5.15.4-2

Notes

- qt6-svg <not-affected> (Fixed before initial upload to the archive)
[bullseye] - qtsvg-opensource-src <no-dsa> (Minor issue)
[buster] - qtsvg-opensource-src <no-dsa> (Minor issue)
[buster] - qt4-x11 <no-dsa> (Minor issue)
https://bugreports.qt.io/browse/QTBUG-91507
https://code.qt.io/cgit/qt/qtsvg.git/commit/?id=7bbf88403fd2d1fe79fab7c8e469f8aeafeb7372 (v5.15.4-lts-lgpl)
Potentially to be considered a duplicte of CVE-2021-3481, ongoing clarification
with the two involved CNAs.

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- qt6-svg <not-affected> (Fixed before initial upload to the archive)[bullseye] - qtsvg-opensource-src <no-dsa> (Minor issue)[buster] - qtsvg-opensource-src <no-dsa> (Minor issue)[buster] - qt4-x11 <no-dsa> (Minor issue)https://bugreports.qt.io/browse/QTBUG-91507https://code.qt.io/cgit/qt/qtsvg.git/commit/?id=7bbf88403fd2d1fe79fab7c8e469f8aeafeb7372 (v5.15.4-lts-lgpl)Potentially to be considered a duplicte of CVE-2021-3481, ongoing clarificationwith the two involved CNAs.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0
bullseye Affected
bookworm Fixed 0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.