SUSE update for libqt4



Published: 2021-12-22
Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2020-17507
CVE-2021-3481
CWE-ID CWE-125
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SUSE Linux Enterprise Workstation Extension
Operating systems & Components / Operating system

SUSE Linux Enterprise Software Development Kit
Operating systems & Components / Operating system

SUSE Linux Enterprise Server
Operating systems & Components / Operating system

libqt4-x11-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-x11-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-32bit
Operating systems & Components / Operating system package or component

libqt4-qt3support-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-qt3support-32bit
Operating systems & Components / Operating system package or component

libqt4-32bit
Operating systems & Components / Operating system package or component

qt4-x11-tools-debuginfo
Operating systems & Components / Operating system package or component

qt4-x11-tools
Operating systems & Components / Operating system package or component

libqt4-x11-debuginfo
Operating systems & Components / Operating system package or component

libqt4-x11
Operating systems & Components / Operating system package or component

libqt4-sql-sqlite-debuginfo
Operating systems & Components / Operating system package or component

libqt4-sql-sqlite
Operating systems & Components / Operating system package or component

libqt4-sql-mysql-debuginfo
Operating systems & Components / Operating system package or component

libqt4-sql-mysql
Operating systems & Components / Operating system package or component

libqt4-sql-debuginfo
Operating systems & Components / Operating system package or component

libqt4-sql
Operating systems & Components / Operating system package or component

libqt4-qt3support-debuginfo
Operating systems & Components / Operating system package or component

libqt4-qt3support
Operating systems & Components / Operating system package or component

libqt4
Operating systems & Components / Operating system package or component

libqt4-devel-doc-data
Operating systems & Components / Operating system package or component

libqt4-private-headers-devel
Operating systems & Components / Operating system package or component

libqt4-linguist-debuginfo
Operating systems & Components / Operating system package or component

libqt4-linguist
Operating systems & Components / Operating system package or component

libqt4-devel-doc-debugsource
Operating systems & Components / Operating system package or component

libqt4-devel-doc-debuginfo
Operating systems & Components / Operating system package or component

libqt4-devel-doc
Operating systems & Components / Operating system package or component

libqt4-devel-debuginfo
Operating systems & Components / Operating system package or component

libqt4-devel
Operating systems & Components / Operating system package or component

libqt4-debuginfo
Operating systems & Components / Operating system package or component

libqt4-sql-unixODBC-debuginfo
Operating systems & Components / Operating system package or component

libqt4-sql-unixODBC-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-unixODBC
Operating systems & Components / Operating system package or component

libqt4-sql-unixODBC-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-sqlite-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-sqlite-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-postgresql-debuginfo
Operating systems & Components / Operating system package or component

libqt4-sql-postgresql-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-postgresql
Operating systems & Components / Operating system package or component

libqt4-sql-postgresql-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-plugins-debugsource
Operating systems & Components / Operating system package or component

libqt4-sql-mysql-debuginfo-32bit
Operating systems & Components / Operating system package or component

libqt4-sql-mysql-32bit
Operating systems & Components / Operating system package or component

libqt4-debugsource
Operating systems & Components / Operating system package or component

libqt4-debuginfo-32bit
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Out-of-bounds read

EUVDB-ID: #VU46199

Risk: Medium

CVSSv3.1: 4.6 [AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-17507

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to buffer over-read. A remote attacker can perform a denial of service attack.

Mitigation

Update the affected package libqt4 to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Workstation Extension: 12-SP5

SUSE Linux Enterprise Software Development Kit: 12-SP5

SUSE Linux Enterprise Server: 12-SP5

libqt4-x11-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-x11-32bit: before 4.8.7-8.16.1

libqt4-sql-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-32bit: before 4.8.7-8.16.1

libqt4-qt3support-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-qt3support-32bit: before 4.8.7-8.16.1

libqt4-32bit: before 4.8.7-8.16.1

qt4-x11-tools-debuginfo: before 4.8.7-8.16.2

qt4-x11-tools: before 4.8.7-8.16.2

libqt4-x11-debuginfo: before 4.8.7-8.16.1

libqt4-x11: before 4.8.7-8.16.1

libqt4-sql-sqlite-debuginfo: before 4.8.7-8.16.1

libqt4-sql-sqlite: before 4.8.7-8.16.1

libqt4-sql-mysql-debuginfo: before 4.8.7-8.16.1

libqt4-sql-mysql: before 4.8.7-8.16.1

libqt4-sql-debuginfo: before 4.8.7-8.16.1

libqt4-sql: before 4.8.7-8.16.1

libqt4-qt3support-debuginfo: before 4.8.7-8.16.1

libqt4-qt3support: before 4.8.7-8.16.1

libqt4: before 4.8.7-8.16.1

libqt4-devel-doc-data: before 4.8.7-8.16.2

libqt4-private-headers-devel: before 4.8.7-8.16.1

libqt4-linguist-debuginfo: before 4.8.7-8.16.1

libqt4-linguist: before 4.8.7-8.16.1

libqt4-devel-doc-debugsource: before 4.8.7-8.16.2

libqt4-devel-doc-debuginfo: before 4.8.7-8.16.2

libqt4-devel-doc: before 4.8.7-8.16.2

libqt4-devel-debuginfo: before 4.8.7-8.16.1

libqt4-devel: before 4.8.7-8.16.1

libqt4-debuginfo: before 4.8.7-8.16.1

libqt4-sql-unixODBC-debuginfo: before 4.8.7-8.16.1

libqt4-sql-unixODBC-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-unixODBC: before 4.8.7-8.16.1

libqt4-sql-unixODBC-32bit: before 4.8.7-8.16.1

libqt4-sql-sqlite-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-sqlite-32bit: before 4.8.7-8.16.1

libqt4-sql-postgresql-debuginfo: before 4.8.7-8.16.1

libqt4-sql-postgresql-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-postgresql: before 4.8.7-8.16.1

libqt4-sql-postgresql-32bit: before 4.8.7-8.16.1

libqt4-sql-plugins-debugsource: before 4.8.7-8.16.1

libqt4-sql-mysql-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-mysql-32bit: before 4.8.7-8.16.1

libqt4-debugsource: before 4.8.7-8.16.1

libqt4-debuginfo-32bit: before 4.8.7-8.16.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20214155-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds read

EUVDB-ID: #VU66866

Risk: Medium

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-3481

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information or crash the application.

The vulnerability exists due to a boundary condition within the QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase when rendering and displaying a crafted Scalable Vector Graphics (SVG) file. A remote attacker can create a specially crafted SVG file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system or crash the application.

Mitigation

Update the affected package libqt4 to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Workstation Extension: 12-SP5

SUSE Linux Enterprise Software Development Kit: 12-SP5

SUSE Linux Enterprise Server: 12-SP5

libqt4-x11-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-x11-32bit: before 4.8.7-8.16.1

libqt4-sql-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-32bit: before 4.8.7-8.16.1

libqt4-qt3support-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-qt3support-32bit: before 4.8.7-8.16.1

libqt4-32bit: before 4.8.7-8.16.1

qt4-x11-tools-debuginfo: before 4.8.7-8.16.2

qt4-x11-tools: before 4.8.7-8.16.2

libqt4-x11-debuginfo: before 4.8.7-8.16.1

libqt4-x11: before 4.8.7-8.16.1

libqt4-sql-sqlite-debuginfo: before 4.8.7-8.16.1

libqt4-sql-sqlite: before 4.8.7-8.16.1

libqt4-sql-mysql-debuginfo: before 4.8.7-8.16.1

libqt4-sql-mysql: before 4.8.7-8.16.1

libqt4-sql-debuginfo: before 4.8.7-8.16.1

libqt4-sql: before 4.8.7-8.16.1

libqt4-qt3support-debuginfo: before 4.8.7-8.16.1

libqt4-qt3support: before 4.8.7-8.16.1

libqt4: before 4.8.7-8.16.1

libqt4-devel-doc-data: before 4.8.7-8.16.2

libqt4-private-headers-devel: before 4.8.7-8.16.1

libqt4-linguist-debuginfo: before 4.8.7-8.16.1

libqt4-linguist: before 4.8.7-8.16.1

libqt4-devel-doc-debugsource: before 4.8.7-8.16.2

libqt4-devel-doc-debuginfo: before 4.8.7-8.16.2

libqt4-devel-doc: before 4.8.7-8.16.2

libqt4-devel-debuginfo: before 4.8.7-8.16.1

libqt4-devel: before 4.8.7-8.16.1

libqt4-debuginfo: before 4.8.7-8.16.1

libqt4-sql-unixODBC-debuginfo: before 4.8.7-8.16.1

libqt4-sql-unixODBC-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-unixODBC: before 4.8.7-8.16.1

libqt4-sql-unixODBC-32bit: before 4.8.7-8.16.1

libqt4-sql-sqlite-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-sqlite-32bit: before 4.8.7-8.16.1

libqt4-sql-postgresql-debuginfo: before 4.8.7-8.16.1

libqt4-sql-postgresql-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-postgresql: before 4.8.7-8.16.1

libqt4-sql-postgresql-32bit: before 4.8.7-8.16.1

libqt4-sql-plugins-debugsource: before 4.8.7-8.16.1

libqt4-sql-mysql-debuginfo-32bit: before 4.8.7-8.16.1

libqt4-sql-mysql-32bit: before 4.8.7-8.16.1

libqt4-debugsource: before 4.8.7-8.16.1

libqt4-debuginfo-32bit: before 4.8.7-8.16.1

External links

http://www.suse.com/support/update/announcement/2021/suse-su-20214155-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###