openSUSE: 2021:1641-1 important: djvulibre
Description
This update for djvulibre fixes the following issues: - CVE-2021-32490 [bsc#1185895]: Out of bounds write in function DJVU:filter_bv() via crafted djvu file - CVE-2021-32491 [bsc#1185900]: Integer overflow in function render() in tools/ddjvu via crafted djvu file - CVE-2021-32492 [bsc#1185904]: Out of bounds read in function DJVU:DataPool:has_data() via crafted djvu file - CVE-2021-32493 [bsc#1185905]: Heap buffer overflow in function DJVU:GBitmap:decode() via crafted djvu file
Patch
Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-1641=1
Package List
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): djvulibre-3.5.27-11.3.1 djvulibre-debuginfo-3.5.27-11.3.1 djvulibre-debugsource-3.5.27-11.3.1 libdjvulibre-devel-3.5.27-11.3.1 libdjvulibre21-3.5.27-11.3.1 libdjvulibre21-debuginfo-3.5.27-11.3.1 - openSUSE Leap 15.3 (noarch): djvulibre-doc-3.5.27-11.3.1
References
https://www.suse.com/security/cve/CVE-2021-32490.html https://www.suse.com/security/cve/CVE-2021-32491.html https://www.suse.com/security/cve/CVE-2021-32492.html https://www.suse.com/security/cve/CVE-2021-32493.html https://bugzilla.suse.com/1185895 https://bugzilla.suse.com/1185900 https://bugzilla.suse.com/1185904 https://bugzilla.suse.com/1185905