PT-2021-3123 · Djvulibre+5 · Djvulibre+5
1Vanchen
+1
·
Published
2021-05-11
·
Updated
2025-10-14
·
CVE-2021-32491
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DjVuLibre versions 3.5.28 and earlier
Description
The issue is related to an integer overflow in the
render() function in the tools/ddjvu component of DjVuLibre. This can be exploited by a remote attacker using a crafted djvu file, potentially leading to an application crash and other consequences.Recommendations
For DjVuLibre versions 3.5.28 and earlier, consider disabling the
render() function in tools/ddjvu as a temporary workaround until a patch is available. Restrict the use of crafted djvu files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Djvulibre
Linuxmint
Suse
Ubuntu