CVE-2019-15143 PUBLISHED

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.

EPSS 0.88% · 75.2th percentile

Risk Scores

EPSS Score
0.88%
75.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSdjvulibre0, 3.5.27.1-7, 3.5.27.1-8
Ubuntu:16.04:LTSdjvulibre0, 3.5.27.1-5, 3.5.27.1-3

Timeline

References

Open in Interactive Console →