Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2021-0247 Moderate: Djvulibre Stack Overflow and Errors

mageia
Calendar Grey June 13, 2021
Dist Mageia Esm H88
Recent enhancements to djvulibre packages tackle various security vulnerabilities highlighted in Mageia. Ensure your system's safety by applying updates promptly.
Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file

Summary

Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file. (CVE-2021-3500).
Out of bounds write in function DJVU::filter_bv() via crafted djvu file. (CVE-2021-32490).
Integer overflow in function render() in tools/ddjvu via crafted djvu file. (CVE-2021-32491)
Out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file. (CVE-2021-32492).
Heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file. (CVE-2021-32493).

References

- https://bugs.mageia.org/show_bug.cgi?id=29000

- https://lists.debian.org/debian-lts-announce/2021/05/msg00022.html

- https://ubuntu.com/security/notices/USN-4957-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/AFBA3B7ZE5WL3W3IC3SJOZLTIMZPKXES/

- https://www.cve.org/CVERecord?id=CVE-2021-3500

- https://www.cve.org/CVERecord?id=CVE-2021-32490

- https://www.cve.org/CVERecord?id=CVE-2021-32491

- https://www.cve.org/CVERecord?id=CVE-2021-32492

- https://www.cve.org/CVERecord?id=CVE-2021-32493

Resolution

SRPMS

- 8/core/djvulibre-3.5.28-1.1.mga8

- 7/core/djvulibre-3.5.27-5.2.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 13 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0247.html
Type: security
CVE: CVE-2021-3500, CVE-2021-32490, CVE-2021-32491, CVE-2021-32492, CVE-2021-32493

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here