CVE-2019-15144 PUBLISHED

In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.

EPSS 0.66% · 70.9th percentile

Risk Scores

EPSS Score
0.66%
70.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSdjvulibre0, 3.5.27.1-3, 3.5.27.1-4
Ubuntu:18.04:LTSdjvulibre0, 3.5.27.1-7, 3.5.27.1-8

Timeline

References

Open in Interactive Console →