First published: Sun Aug 18 2019(Updated: )
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Djvulibre Project Djvulibre | =3.5.27 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Canonical Ubuntu Linux | =19.10 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
debian/djvulibre | 3.5.28-2 | |
ubuntu/djvulibre | <3.5.27.1-8ubuntu0.1 | 3.5.27.1-8ubuntu0.1 |
ubuntu/djvulibre | <3.5.27.1-10ubuntu0.1 | 3.5.27.1-10ubuntu0.1 |
ubuntu/djvulibre | <3.5.27.1-11 | 3.5.27.1-11 |
ubuntu/djvulibre | <3.5.27.1-5ubuntu0.1 | 3.5.27.1-5ubuntu0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-15142 is medium with a severity value of 5.5.
Attackers can exploit CVE-2019-15142 by crafting a malicious DJVU file that triggers a heap-based buffer over-read in the DJVU reader component of DjVuLibre, causing a denial-of-service (application crash).
The affected software versions include DjVuLibre 3.5.27 up to but not including 3.5.27.1-8ubuntu0.1, DjVuLibre 3.5.27 up to but not including 3.5.27.1-10ubuntu0.1, DjVuLibre 3.5.27 up to but not including 3.5.27.1-11, DjVuLibre 3.5.27 up to but not including 3.5.27.1-5ubuntu0.1, DjVuLibre 3.5.27 up to but not including 3.5.28-2, Djvulibre Project Djvulibre 3.5.27, Debian Debian Linux 8.0, Debian Debian Linux 9.0, Debian Debian Linux 10.0, Debian Debian Linux 11.0, Fedoraproject Fedora 29, Fedoraproject Fedora 30, Fedoraproject Fedora 31, Canonical Ubuntu Linux 16.04 (ESM), Canonical Ubuntu Linux 18.04 (LTS), Canonical Ubuntu Linux 19.04, Canonical Ubuntu Linux 19.10, openSUSE Leap 15.0, and openSUSE Leap 15.1.
To fix CVE-2019-15142 in DjVuLibre, update to version 3.5.27.1-8ubuntu0.1, 3.5.27.1-10ubuntu0.1, 3.5.27.1-11, 3.5.27.1-5ubuntu0.1, or 3.5.28-2 depending on the specific affected version.
You can find more information about CVE-2019-15142 from the following sources: [link1], [link2], [link3].