CVE-2021-32491 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A security issue was found in djvulibre. An integer overflow in the function render() in tools/ddjvu may lead to an application crash and other consequences via a crafted djvu file.
Group Package Affected Fixed Severity Status Ticket
AVG-1899 djvulibre 3.5.28-2 3.5.28-3 Medium Fixed FS#70787
Date Advisory Group Package Severity Type
25 May 2021 ASA-202105-18 AVG-1899 djvulibre Medium arbitrary code execution
References
https://bugzilla.redhat.com/show_bug.cgi?id=1943684
https://bugzilla.redhat.com/show_bug.cgi?id=1943409
https://bugzilla.redhat.com/attachment.cgi?id=1770218&action=diff
https://src.fedoraproject.org/rpms/djvulibre/blob/4b8d9b4bcb10c24739ca2dcd68a7fba4abe90860/f/djvulibre-3.5.27-integer-overflow.patch