CVE-2021-3500 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
A security issue was found in djvulibre. A stack overflow in the function DJVU::DjVuDocument::get_djvu_file() may lead to an application crash and other consequences via a crafted djvu file.
Group Package Affected Fixed Severity Status Ticket
AVG-1899 djvulibre 3.5.28-2 3.5.28-3 Medium Fixed FS#70787
Date Advisory Group Package Severity Type
25 May 2021 ASA-202105-18 AVG-1899 djvulibre Medium arbitrary code execution
References
https://bugzilla.redhat.com/show_bug.cgi?id=1943685
https://bugzilla.redhat.com/show_bug.cgi?id=1943411
https://src.fedoraproject.org/rpms/djvulibre/blob/rawhide/f/djvulibre-3.5.27-djvuport-stack-overflow.patch