CVE-2021-3630

Name
CVE-2021-3630
Description
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://bugzilla.redhat.com/show_bug.cgi?id=1977427
Mailing List https://lists.debian.org/debian-lts-announce/2021/07/msg00002.html
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q3B4QZCICPZRDXA2HOIACSQNZB2VEHSM/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XVKYWV4P5XGA3FXKGFB443MKC32L7YQB/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MRXCW4BUGAJLGF6IWQWUZ2YBICMZCPK/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIZIAJWGKI26DKDOGJS7J7CIQGHHMIHG/
DEBIAN https://www.debian.org/security/2021/dsa-5032

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:djvulibre_project:djvulibre:*:*:*:*:*:*:*:* djvulibre >= None < 3.5.28

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
djvulibre 3.15-community 3.5.28-r1 Leon Bottou <leonb@bottou.org> fixed
djvulibre 3.16-community 3.5.28-r1 Leon Bottou <leonb@bottou.org> fixed