CVE-2019-15145: Medium severity Djvulibre Project Djvulibre vulnerability
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::getdirectcontext in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-15145?
CVE-2019-15145 is a vulnerability in DjVuLibre 3.5.27 that allows attackers to cause a denial-of-service attack by crafting a corrupted JB2 image file.
How severe is CVE-2019-15145?
CVE-2019-15145 has a severity rating of 5.5 (medium).
How do I fix CVE-2019-15145?
To fix CVE-2019-15145, update DjVuLibre to version 3.5.27.1-8ubuntu0.1 (for Ubuntu) or apply the corresponding update for your operating system.
Where can I find more information about CVE-2019-15145?
You can find more information about CVE-2019-15145 in the provided references: [link1], [link2], [link3].
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-15145?
The CWE ID for CVE-2019-15145 is CWE-125.