ALT-PU-2022-3252-1
Closed vulnerabilities
Published: 2021-06-25
BDU:2021-03577
Уязвимость функции DJVU::DjVuTXT::decode() набора библиотек и утилит для просмотра, создания и редактирования DjVu-файлов DjVuLibre, позволяющая нарушителю вызвать отказ в обслуживании
Severity: MEDIUM (6.5)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
Published: 2021-06-30
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-3630
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- https://bugzilla.redhat.com/show_bug.cgi?id=1977427
- https://bugzilla.redhat.com/show_bug.cgi?id=1977427
- [debian-lts-announce] 20210703 [SECURITY] [DLA 2702-1] djvulibre security update
- [debian-lts-announce] 20210703 [SECURITY] [DLA 2702-1] djvulibre security update
- FEDORA-2021-6422a16aed
- FEDORA-2021-6422a16aed
- FEDORA-2021-d19172badb
- FEDORA-2021-d19172badb
- FEDORA-2021-7514c11a37
- FEDORA-2021-7514c11a37
- FEDORA-2021-fd6f2727c8
- FEDORA-2021-fd6f2727c8
- DSA-5032
- DSA-5032
Closed bugs
"any2djvu -q" returns wrong status code