6.8
CVSSv2

CVE-2021-32490

Published: 24/06/2021 Updated: 09/03/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in djvulibre-3.5.28 and previous versions. An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djvulibre project djvulibre

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Several vulnerabilities were discovered in djvulibre, a library and set of tools to handle documents in the DjVu format An attacker could crash document viewers and possibly execute arbitrary code through crafted DjVu files For the oldstable distribution (buster), these problems have been fixed in version 35271-10+deb10u1 For the stable distr ...
A flaw was found in djvulibre-3528 and earlier An out of bounds write in function DJVU::filter_bv() via crafted djvu file may lead to application crash and other consequences (CVE-2021-32490) A flaw was found in djvulibre-3528 and earlier An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to application cr ...
A security issue was found in djvulibre An out of bounds write in the function DJVU::filter_bv() may lead to an application crash and other consequences via a crafted djvu file ...