CVE-2021-32490 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A security issue was found in djvulibre. An out of bounds write in the function DJVU::filter_bv() may lead to an application crash and other consequences via a crafted djvu file.
Group Package Affected Fixed Severity Status Ticket
AVG-1899 djvulibre 3.5.28-2 3.5.28-3 Medium Fixed FS#70787
Date Advisory Group Package Severity Type
25 May 2021 ASA-202105-18 AVG-1899 djvulibre Medium arbitrary code execution
References
https://bugzilla.redhat.com/show_bug.cgi?id=1943693
https://bugzilla.redhat.com/show_bug.cgi?id=1943408
https://bugzilla.redhat.com/attachment.cgi?id=1770184&action=diff
https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-check-image-size.patch