- ----------------------------------------------------------------------- Debian LTS Advisory DLA-2702-1 [email protected] https://www.debian.org/lts/security/ Utkarsh Gupta July 03, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : djvulibre Version : 3.5.27.1-7+deb9u2 CVE ID : CVE-2021-3630 An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. For Debian 9 stretch, this problem has been fixed in version 3.5.27.1-7+deb9u2. We recommend that you upgrade your djvulibre packages. For the detailed security status of djvulibre please refer to its security tracker page at: https://security-tracker.debian.org/tracker/djvulibre Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS