#VU21452 Infinite loop in DjVuLibre - CVE-2019-15144
Published: September 30, 2019
DjVuLibre
DjVu
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in the sorting functionality (aka GArrayTemplate::sort) within the libdjvu/GContainer.h in DjVuLibre. A remote attacker can consume excessive system resources with a specially crafted BMP file.