CVE-2019-15143

In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
djvulibre_projectdjvulibre
3.5.27
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
debiandebian_linux
11.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.04
canonicalubuntu_linux
19.10
opensuseleap
15.0
opensuseleap
15.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
djvulibre
bookworm
3.5.28-2
fixed
bullseye
3.5.28-2
fixed
sid
3.5.28-2
fixed
trixie
3.5.28-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
djvulibre
bionic
Fixed 3.5.27.1-8ubuntu0.1
released
disco
Fixed 3.5.27.1-10ubuntu0.1
released
eoan
not-affected
trusty
dne
xenial
Fixed 3.5.27.1-5ubuntu0.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libdjvulibre-devel
suse enterprise desktop 15
3.5.27-3.3.1
fixed
suse enterprise desktop 15 SP1
3.5.27-3.3.1
fixed
suse enterprise desktop 15 SP2
3.5.27-9.28
fixed
suse enterprise desktop 15 SP3
3.5.27-9.28
fixed
suse enterprise desktop 15 SP4
3.5.27-11.11.1
fixed
suse enterprise desktop 15 SP5
3.5.27-11.11.1
fixed
suse enterprise desktop 15 SP6
3.5.27-150200.11.14.1
fixed
suse enterprise desktop 15 SP7
3.5.27-150200.11.14.1
fixed
suse enterprise sap 15
3.5.27-3.3.1
fixed
suse enterprise sap 15 SP1
3.5.27-3.3.1
fixed
suse enterprise sap 15 SP2
3.5.27-9.28
fixed
suse enterprise sap 15 SP3
3.5.27-9.28
fixed
suse enterprise sap 15 SP4
3.5.27-11.11.1
fixed
suse enterprise sap 15 SP5
3.5.27-11.11.1
fixed
suse enterprise sap 15 SP6
3.5.27-150200.11.14.1
fixed
suse enterprise sap 15 SP7
3.5.27-150200.11.14.1
fixed
suse enterprise server 15
3.5.27-3.3.1
fixed
suse enterprise server 15 SP1
3.5.27-3.3.1
fixed
suse enterprise server 15 SP2
3.5.27-9.28
fixed
suse enterprise server 15 SP3
3.5.27-9.28
fixed
suse enterprise server 15 SP4
3.5.27-11.11.1
fixed
suse enterprise server 15 SP5
3.5.27-11.11.1
fixed
suse enterprise server 15 SP6
3.5.27-150200.11.14.1
fixed
suse enterprise server 15 SP7
3.5.27-150200.11.14.1
fixed
libdjvulibre21
suse enterprise desktop 15
3.5.27-3.3.1
fixed
suse enterprise desktop 15 SP1
3.5.27-3.3.1
fixed
suse enterprise desktop 15 SP2
3.5.27-9.28
fixed
suse enterprise desktop 15 SP3
3.5.27-9.28
fixed
suse enterprise desktop 15 SP4
3.5.27-11.11.1
fixed
suse enterprise desktop 15 SP5
3.5.27-11.11.1
fixed
suse enterprise desktop 15 SP6
3.5.27-150200.11.14.1
fixed
suse enterprise desktop 15 SP7
3.5.27-150200.11.14.1
fixed
suse enterprise sap 15
3.5.27-3.3.1
fixed
suse enterprise sap 15 SP1
3.5.27-3.3.1
fixed
suse enterprise sap 15 SP2
3.5.27-9.28
fixed
suse enterprise sap 15 SP3
3.5.27-9.28
fixed
suse enterprise sap 15 SP4
3.5.27-11.11.1
fixed
suse enterprise sap 15 SP5
3.5.27-11.11.1
fixed
suse enterprise sap 15 SP6
3.5.27-150200.11.14.1
fixed
suse enterprise sap 15 SP7
3.5.27-150200.11.14.1
fixed
suse enterprise server 15
3.5.27-3.3.1
fixed
suse enterprise server 15 SP1
3.5.27-3.3.1
fixed
suse enterprise server 15 SP2
3.5.27-9.28
fixed
suse enterprise server 15 SP3
3.5.27-9.28
fixed
suse enterprise server 15 SP4
3.5.27-11.11.1
fixed
suse enterprise server 15 SP5
3.5.27-11.11.1
fixed
suse enterprise server 15 SP6
3.5.27-150200.11.14.1
fixed
suse enterprise server 15 SP7
3.5.27-150200.11.14.1
fixed
References