CVE-2019-15143: Medium severity Djvulibre Project Djvulibre vulnerability
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::readrleraw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-15143?
CVE-2019-15143 is a vulnerability in DjVuLibre 3.5.27 that allows attackers to cause a denial-of-service error.
How severe is CVE-2019-15143?
CVE-2019-15143 has a severity rating of 5.5 (medium).
Which software versions are affected by CVE-2019-15143?
CVE-2019-15143 affects DjVuLibre 3.5.27 up to exclusive 3.5.27.1-8ubuntu0.1, 3.5.27.1-10ubuntu0.1, 3.5.27.1-11, and 3.5.27.1-5ubuntu0.1.
How can I fix CVE-2019-15143?
To fix CVE-2019-15143, update the affected software to version 3.5.27.1-8ubuntu0.1, 3.5.27.1-10ubuntu0.1, 3.5.27.1-11, or 3.5.27.1-5ubuntu0.1.
Where can I find more information about CVE-2019-15143?
You can find more information about CVE-2019-15143 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00086.html), [2](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00087.html), [3](https://lists.debian.org/debian-lts-announce/2019/08/msg00036.html).