PT-2023-5261 · Djvulibre+7 · Djvulibre+7

Zfeixq

·

Published

2023-08-22

·

Updated

2026-02-23

·

CVE-2021-46312

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions DjVuLibre version 3.5.28
Description The issue is related to a lack of check for division by zero in the IW44EncodeCodec.cpp component of the DjVuLibre library, which is used for viewing, creating, and editing DjVu files. This can be exploited by a remote attacker to cause a denial of service. The vulnerability allows attackers to cause a denial of service via divide by zero.
Recommendations For DjVuLibre version 3.5.28, consider disabling the IW44EncodeCodec.cpp component as a temporary workaround until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1169
ALT-PU-2025-12685
ALT-PU-2025-12687
BDU:2023-05878
CVE-2021-46312
DLA-4247-1
MGASA-2024-0183
OESA-2023-1641
OPENSUSE-SU-2023_3520-1
OPENSUSE-SU-2024:13178-1
ROSA-SA-2024-2428
SUSE-SU-2023:3520-1
SUSE-SU-2023:3755-1
USN-8054-1

Affected Products

Alt Linux
Astra Linux
Debian
Djvulibre
Linuxmint
Red Os
Suse
Ubuntu