Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian 9 DLA-2667-1: Critical Djvulibre Document Flaws Allow Code Execution

debian lts
Calendar Grey May 26, 2021
Dist Debian Esm H88
Enhance the djvulibre software to mitigate several severe vulnerabilities that could lead to remote code execution through specially designed DjVu documents.
Several vulnerabilities were discovered in djvulibre, a library and set of tools to handle documents in the DjVu format

Summary

For Debian 9 stretch, these problems have been fixed in version
3.5.27.1-7+deb9u1.

We recommend that you upgrade your djvulibre packages.

For the detailed security status of djvulibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/djvulibre

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: djvulibre
Version: 3.5.27.1-7+deb9u1
CVE ID: CVE-2019-15142 CVE-2019-15143 CVE-2019-15144 CVE-2019-15145
Debian Bug: 945114 988215

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here