Infinite loop in DjVuLibre - CVE-2019-15143

 

Infinite loop in DjVuLibre - CVE-2019-15143

Published: September 30, 2019


Vulnerability identifier: #VU21451
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15143
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop in bitmap reader component in DjVuLibre, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp files. A remote attacker can create a specially crafted file, pass it to the application using the affected library and perform denial of service conditions.


Affected software

DjVuLibre
Gentoo Linux
Fedora
Opensuse
openEuler
djvulibre (Debian package)
djvulibre (Ubuntu package)
djvulibre
mingw-djvulibre
djvulibre-debugsource
djvulibre-debuginfo
djvulibre-devel
djvulibre-help

How to mitigate CVE-2019-15143

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

djvulibre (Debian package) - addressed in versions 3.5.27.1-10+deb10u1, 3.5.28-2
djvulibre (Ubuntu package) - addressed in versions 3.5.27.1-5ubuntu0.1, 3.5.27.1-8ubuntu0.1, 3.5.27.1-10ubuntu0.1, 3.5.27.1-13ubuntu0.1
djvulibre - addressed in versions 3.5.25.3-18.el6, 3.5.25.3-18.el7, 3.5.27-14.fc29, 3.5.27-15.fc30, 3.5.27-16.fc31
mingw-djvulibre - addressed in versions 3.5.27-7.fc30, 3.5.27-7.fc31
djvulibre-debugsource - update to 3.5.27-15
djvulibre-debuginfo - update to 3.5.27-15
djvulibre-devel - update to 3.5.27-15
djvulibre-help - update to 3.5.27-15
djvulibre - update to 3.5.27-15

External References

Related Security Bulletins