{
  "schema_version": "1.6.2",
  "id": "MGASA-2021-0247",
  "published": "2021-06-13T21:32:39Z",
  "modified": "2021-06-13T20:16:11Z",
  "summary": "Updated djvulibre packages fix security vulnerabilities",
  "details": "Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted \ndjvu file. (CVE-2021-3500).\n\nOut of bounds write in function DJVU::filter_bv()\nvia crafted djvu file. (CVE-2021-32490).\n\nInteger overflow in function render() in tools/ddjvu via crafted djvu file.\n(CVE-2021-32491)\n\nOut of bounds read in function DJVU::DataPool::has_data() via crafted djvu \nfile. (CVE-2021-32492).\n\nHeap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu \nfile. (CVE-2021-32493).\n",
  "related": [
    "CVE-2021-3500",
    "CVE-2021-32490",
    "CVE-2021-32491",
    "CVE-2021-32492",
    "CVE-2021-32493"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2021-0247.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=29000"
    },
    {
      "type": "REPORT",
      "url": "https://www.debian.org/lts/security/2021/dla-2667"
    },
    {
      "type": "REPORT",
      "url": "https://ubuntu.com/security/notices/USN-4957-1"
    },
    {
      "type": "REPORT",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/AFBA3B7ZE5WL3W3IC3SJOZLTIMZPKXES/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "djvulibre",
        "purl": "pkg:rpm/mageia/djvulibre?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.5.27-5.2.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "djvulibre",
        "purl": "pkg:rpm/mageia/djvulibre?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.5.28-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
