CVE-2021-30354: Integer Overflow
Published Sep 1, 2021
·Updated
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code execution when parsing a crafted PDF book.
Affected Software
2 affected components
Amazon Kindle Firmware<=5.13.4
Amazon Kindle
Event History
Sep 1, 2021
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-30354.
2
What is the severity of CVE-2021-30354?
The severity of CVE-2021-30354 is critical with a CVSS score of 8.6.
3
Which software versions are affected by CVE-2021-30354?
Amazon Kindle e-reader prior to and including version 5.13.4 is affected by CVE-2021-30354.
4
What is the description of CVE-2021-30354?
CVE-2021-30354 is an Integer Overflow vulnerability in Amazon Kindle e-reader that leads to a Heap-Based Buffer Overflow and allows for memory corruption and code execution when parsing a crafted PDF book.
5
Is the Amazon Kindle device itself vulnerable?
No, the Amazon Kindle device itself is not vulnerable to CVE-2021-30354.