PT-2021-3527 · Djvulibre+4 · Djvulibre+4

Guilherme De Almeida Suckevicz

·

Published

2021-06-25

·

Updated

2022-12-01

·

CVE-2021-3630

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions DjVuLibre versions prior to 3.5.28
Description An out-of-bounds write issue was found in the DJVU::DjVuTXT::decode() function in DjVuText.cpp via a crafted djvu file, which may lead to a crash and segmentation fault. This flaw can be exploited by a remote attacker using a specially crafted djvu file, potentially causing a denial of service.
Recommendations For versions prior to 3.5.28, update to version 3.5.28 or later to resolve the issue. As a temporary workaround, consider disabling the DJVU::DjVuTXT::decode() function until a patch is available.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1603
ALT-PU-2022-3240
ALT-PU-2022-3252
BDU:2021-03577
CVE-2021-3630
DLA-2702-1
DSA-5032-1
OESA-2021-1266
OPENSUSE-SU-2021:1112-1
OPENSUSE-SU-2021:2619-1
OPENSUSE-SU-2021_1112-1
OPENSUSE-SU-2021_2619-1
OPENSUSE-SU-2024:12946-1
SUSE-SU-2021:14761-1
SUSE-SU-2021:14773-1
SUSE-SU-2021:2619-1
SUSE-SU-2021:2621-1
SUSE-SU-2021:2796-1
SUSE-SU-2021_14761-1
SUSE-SU-2021_14773-1
SUSE-SU-2021_2619-1
SUSE-SU-2021_2621-1
SUSE-SU-2021_2796-1
USN-5005-1

Affected Products

Alt Linux
Astra Linux
Djvulibre
Suse
Ubuntu