First published: Wed Sep 01 2021(Updated: )
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBig2Image::expand() and results in a memory corruption that leads to code execution when parsing a crafted PDF book.
Credit: cve@checkpoint.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Kindle Firmware | <=5.13.4 | |
Amazon Kindle |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-30354.
The severity of CVE-2021-30354 is critical with a CVSS score of 8.6.
Amazon Kindle e-reader prior to and including version 5.13.4 is affected by CVE-2021-30354.
CVE-2021-30354 is an Integer Overflow vulnerability in Amazon Kindle e-reader that leads to a Heap-Based Buffer Overflow and allows for memory corruption and code execution when parsing a crafted PDF book.
No, the Amazon Kindle device itself is not vulnerable to CVE-2021-30354.