CVE-2021-32491: Integer Overflow
A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.
Other sources
A flaw was found in latest djvulibre. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application crash and other consequences.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1943409
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32491?
CVE-2021-32491 is a vulnerability found in djvulibre-3.5.28 and earlier that can lead to application crashes and other consequences.
How does CVE-2021-32491 affect the affected software?
CVE-2021-32491 affects djvulibre-3.5.28 and earlier versions on Debian Linux 10.0 and 11.0, as well as Djvulibre Project Djvulibre, potentially leading to application crashes and other consequences.
What is the severity of CVE-2021-32491?
CVE-2021-32491 has a severity score of 7.8, which is considered high.
How can I fix CVE-2021-32491?
To fix CVE-2021-32491, it is recommended to update to the latest version of djvulibre (at least version 3.5.28-2) or apply the provided patches from the Debian repository.
Where can I find more information about CVE-2021-32491?
More information about CVE-2021-32491 can be found on the Red Hat Bugzilla, SourceForge, and Debian Security Tracker websites.