CVE-2021-3630
published 2021-06-30CVE-2021-3630: An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.05%
60.6th percentile
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | djvulibre | < djvulibre 3.5.27.1-12 (bookworm) | djvulibre 3.5.27.1-12 (bookworm) |
| djvulibre_project | djvulibre | < 3.5.28 | 3.5.28 |
| djvulibre_project | djvulibre | — | — |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-12 | 3.5.27.1-12 |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-12 | 3.5.27.1-12 |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-12 | 3.5.27.1-12 |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-12 | 3.5.27.1-12 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mpc3-cw77-gc2f: An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText
ghsa_unreviewed·2022-05-24
CVE-2021-3630 [MEDIUM] CWE-787 GHSA-mpc3-cw77-gc2f: An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
OSV
CVE-2021-3630: An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText
osv·2021-06-30·CVSS 5.5
CVE-2021-3630 [MEDIUM] CVE-2021-3630: An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
Red Hat
kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios
vendor_redhat·2024-03-01·CVSS 5.5
CVE-2021-47073 [MEDIUM] CWE-99 kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios
kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios
init_dell_smbios_wmi() only registers the dell_smbios_wmi_driver on systems
where the Dell WMI interface is supported. While exit_dell_smbios_wmi()
unregisters it unconditionally, this leads to the following oops:
[ 175.722921] ------------[ cut here ]------------
[ 175.722925] Unexpected driver unregister!
[ 175.722939] WARNING: CPU: 1 PID: 3630 at drivers/base/driver.c:194 driver_unregister+0x38/0x40
...
[ 175.723089] Call Trace:
[ 175.723094] cleanup_module+0x5/0xedd [dell_smbios]
...
[ 175.723148] ---[ end trace 064c34e1ad49509d ]---
Make the unregister happen on the same condition the regi
Ubuntu
DjVuLibre vulnerability
vendor_ubuntu·2021-07-05
CVE-2021-3630 DjVuLibre vulnerability
Title: DjVuLibre vulnerability
Summary: DjVuLibre could be made to crash or execute arbitrary code if it
opened a specially crafted file.
It was discovered that DjVuLibre incorrectly handled certain djvu files.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-3630: djvulibre - An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::de...
vendor_debian·2021·CVSS 5.5
CVE-2021-3630 [MEDIUM] CVE-2021-3630: djvulibre - An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::de...
An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to 3.5.28.
Scope: local
bookworm: resolved (fixed in 3.5.27.1-12)
bullseye: resolved (fixed in 3.5.27.1-12)
forky: resolved (fixed in 3.5.27.1-12)
sid: resolved (fixed in 3.5.27.1-12)
trixie: resolved (fixed in 3.5.27.1-12)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1977427https://lists.debian.org/debian-lts-announce/2021/07/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MRXCW4BUGAJLGF6IWQWUZ2YBICMZCPK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIZIAJWGKI26DKDOGJS7J7CIQGHHMIHG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3B4QZCICPZRDXA2HOIACSQNZB2VEHSM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVKYWV4P5XGA3FXKGFB443MKC32L7YQB/https://www.debian.org/security/2021/dsa-5032https://bugzilla.redhat.com/show_bug.cgi?id=1977427https://lists.debian.org/debian-lts-announce/2021/07/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MRXCW4BUGAJLGF6IWQWUZ2YBICMZCPK/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIZIAJWGKI26DKDOGJS7J7CIQGHHMIHG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q3B4QZCICPZRDXA2HOIACSQNZB2VEHSM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XVKYWV4P5XGA3FXKGFB443MKC32L7YQB/https://www.debian.org/security/2021/dsa-5032
2021-06-30
Published