CVE-2021-3630: Medium severity Djvulibre Project Djvulibre vulnerability
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/djvulibreto a version that resolves this vulnerability.Fixed in 3.5.27.1-10+deb10u1Fixed in 3.5.28-2 - Upgrade
Upgrade
redhat/DjVuLibreto a version that resolves this vulnerability.Fixed in 3.5.28 - Upgrade
Upgrade
DjVuLibreto a version that resolves this vulnerability.Fixed in 3.5.28
Event History
Frequently Asked Questions
What is CVE-2021-3630?
CVE-2021-3630 is an out-of-bounds write vulnerability found in DjVuLibre.
How does CVE-2021-3630 affect DjVuLibre?
CVE-2021-3630 may lead to a crash and segmentation fault in DjVuLibre.
Which versions of DjVuLibre are affected by CVE-2021-3630?
DjVuLibre versions prior to 3.5.28 are affected by CVE-2021-3630.
What is the severity of CVE-2021-3630?
CVE-2021-3630 has a severity rating of medium (5.5).
How can I fix CVE-2021-3630?
To fix CVE-2021-3630, update DjVuLibre to version 3.5.28 or later.