Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
[
{
"source": "https://github.com/qt/qtbase/commit/6b400e3147dcfd8cc3a393ace1bd118c93762e0c",
"id": "CVE-2021-38593-10bb0601",
"deprecated": false,
"target": {
"file": "src/gui/painting/qpaintengineex.cpp"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"271928562808682822601995538577538974780",
"72176071764742851516072444134726106676",
"163469072021631174261305783525076176707",
"213547461056257825045409429829012753748"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/qt/qtbase/commit/202143ba41f6ac574f1858214ed8bf4a38b73ccd",
"id": "CVE-2021-38593-22346b8a",
"deprecated": false,
"target": {
"file": "src/gui/painting/qpaintengineex.cpp"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"271928562808682822601995538577538974780",
"72176071764742851516072444134726106676",
"163469072021631174261305783525076176707",
"213547461056257825045409429829012753748"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/qt/qtbase/commit/1ca02cf2879a5e1511a2f2109f0925cf4c892862",
"id": "CVE-2021-38593-2f99537b",
"deprecated": false,
"target": {
"file": "src/gui/painting/qpaintengineex.cpp"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"271928562808682822601995538577538974780",
"72176071764742851516072444134726106676",
"163469072021631174261305783525076176707",
"213547461056257825045409429829012753748"
]
},
"signature_type": "Line"
},
{
"source": "https://github.com/qt/qtbase/commit/1ca02cf2879a5e1511a2f2109f0925cf4c892862",
"id": "CVE-2021-38593-527772bf",
"deprecated": false,
"target": {
"function": "QPaintEngineEx::stroke",
"file": "src/gui/painting/qpaintengineex.cpp"
},
"signature_version": "v1",
"digest": {
"length": 6445.0,
"function_hash": "66084939280504979425354887214909155133"
},
"signature_type": "Function"
},
{
"source": "https://github.com/qt/qtbase/commit/202143ba41f6ac574f1858214ed8bf4a38b73ccd",
"id": "CVE-2021-38593-bbbd8d65",
"deprecated": false,
"target": {
"function": "QPaintEngineEx::stroke",
"file": "src/gui/painting/qpaintengineex.cpp"
},
"signature_version": "v1",
"digest": {
"length": 6445.0,
"function_hash": "66084939280504979425354887214909155133"
},
"signature_type": "Function"
},
{
"source": "https://github.com/qt/qtbase/commit/6b400e3147dcfd8cc3a393ace1bd118c93762e0c",
"id": "CVE-2021-38593-dabe698e",
"deprecated": false,
"target": {
"function": "QPaintEngineEx::stroke",
"file": "src/gui/painting/qpaintengineex.cpp"
},
"signature_version": "v1",
"digest": {
"length": 6445.0,
"function_hash": "66084939280504979425354887214909155133"
},
"signature_type": "Function"
}
]