CVE-2021-32492 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A security issue was found in djvulibre. An out of bounds read in the function DJVU::DataPool::has_data() may lead to an application crash and other consequences via a crafted djvu file.
Group Package Affected Fixed Severity Status Ticket
AVG-1899 djvulibre 3.5.28-2 3.5.28-3 Medium Fixed FS#70787
Date Advisory Group Package Severity Type
25 May 2021 ASA-202105-18 AVG-1899 djvulibre Medium arbitrary code execution
References
https://bugzilla.redhat.com/show_bug.cgi?id=1943686
https://bugzilla.redhat.com/show_bug.cgi?id=1943410
https://bugzilla.redhat.com/attachment.cgi?id=1770220&action=diff
https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-check-input-pool.patch