CVE-2021-32492: Buffer Overflow
A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::hasdata() via crafted djvu file may lead to application crash and other consequences.
Other sources
A flaw was found in latest djvulibre. An out of bounds read in function DJVU::DataPool::hasdata() via crafted djvu file may lead to application crash and other consequences.
References:
https://bugzilla.redhat.com/showbug.cgi?id=1943410
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32492?
The severity of CVE-2021-32492 is high with a CVSS score of 7.8.
How does CVE-2021-32492 affect djvulibre?
CVE-2021-32492 affects djvulibre versions 3.5.28 and earlier.
How can an out of bounds read in djvulibre be exploited?
An out of bounds read in djvulibre can be exploited via a crafted djvu file, leading to application crash and other consequences.
Is there a fix available for CVE-2021-32492 in djvulibre?
Yes, there are fixes available for CVE-2021-32492 in djvulibre versions 3.5.27.1-10+deb10u1 and 3.5.28-2.
Where can I find more information about CVE-2021-32492?
You can find more information about CVE-2021-32492 on the following references: [1] [2] [3]