CVE-2021-32493 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A security issue was found in djvulibre. A heap buffer overflow in the function DJVU::GBitmap::decode() may lead to an application crash and other consequences via a crafted djvu file.
Group Package Affected Fixed Severity Status Ticket
AVG-1899 djvulibre 3.5.28-2 3.5.28-3 Medium Fixed FS#70787
Date Advisory Group Package Severity Type
25 May 2021 ASA-202105-18 AVG-1899 djvulibre Medium arbitrary code execution
References
https://bugzilla.redhat.com/show_bug.cgi?id=1943690
https://bugzilla.redhat.com/show_bug.cgi?id=1943424
https://bugzilla.redhat.com/attachment.cgi?id=1774554&action=diff
https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-unsigned-short-overflow.patch