CVE-2025-53367
published 2025-07-03CVE-2025-53367: DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method…
PriorityP338high8.4CVSS 4.0
AVLACLATNPRNUIAVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.74%
51.0th percentile
DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | djvulibre | < djvulibre 3.5.28-2.1~deb12u1 (bookworm) | djvulibre 3.5.28-2.1~deb12u1 (bookworm) |
| djvulibre_project | djvulibre | >= 0 < 3.5.28-2.2~deb11u1 | 3.5.28-2.2~deb11u1 |
| djvulibre_project | djvulibre | >= 0 < 3.5.28-2.1~deb12u1 | 3.5.28-2.1~deb12u1 |
| djvulibre_project | djvulibre | >= 0 < 3.5.28-2.1 | 3.5.28-2.1 |
| djvulibre_project | djvulibre | >= 0 < 3.5.28-2.1 | 3.5.28-2.1 |
| djvulibre_project | djvulibre | >= 0 < 3.5.28-2ubuntu0.22.04.2 | 3.5.28-2ubuntu0.22.04.2 |
| djvulibre_project | djvulibre | >= 0 < 3.5.28-2ubuntu0.24.04.2 | 3.5.28-2ubuntu0.24.04.2 |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-5ubuntu0.1+esm3 | 3.5.27.1-5ubuntu0.1+esm3 |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-8ubuntu0.4+esm1 | 3.5.27.1-8ubuntu0.4+esm1 |
| djvulibre_project | djvulibre | >= 0 < 3.5.27.1-14ubuntu0.1+esm1 | 3.5.27.1-14ubuntu0.1+esm1 |
| djvunet | djvulibre | < 3.5.29 | 3.5.29 |
CVSS provenance
nvdv4.08.4HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.4HIGH
vendor_debian8.4HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DjVuLibre vulnerabilities
vendor_ubuntu·2026-02-23·CVSS 6.5
CVE-2021-46312 [MEDIUM] DjVuLibre vulnerabilities
Title: DjVuLibre vulnerabilities
Summary: Several security issues were fixed in DjVuLibre.
It was discovered that DjVuLibre could be forced to execute a division
by zero in certain instances. A remote attacker could possibly use
this issue to cause applications to stop responding or crash, resulting
in a denial of service. (CVE-2021-46312)
It was discovered that DjVuLibre incorrectly handled certain memory
operations. If a user or automated system were tricked into processing a
specially crafted DjVu file, a remote attacker could cause applications
to stop responding or crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-53367)
Instructions: In general, a standard syste
Ubuntu
DjVuLibre vulnerability
vendor_ubuntu·2025-07-09
CVE-2025-53367 DjVuLibre vulnerability
Title: DjVuLibre vulnerability
Summary: DjVuLibre could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that DjVuLibre incorrectly handled certain memory
operations. If a user or automated system were tricked into processing a
specially crafted DjVu file, a remote attacker could cause applications
to stop responding or crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2025-53367: djvulibre - DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing...
vendor_debian·2025·CVSS 8.4
CVE-2025-53367 [HIGH] CVE-2025-53367: djvulibre - DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing...
DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.
Scope: local
bookworm: resolved (fixed in 3.5.28-2.1~deb12u1)
bullseye: resolved (fixed in 3.5.28-2.2~deb11u1)
forky: resolved (fixed in 3.5.28-2.1)
sid: resolved (fixed in 3.5.28-2.1)
trixie: resolved (fixed in 3.5.28-2.1)
OSV
djvulibre vulnerabilities
osv·2026-02-23·CVSS 6.5
CVE-2021-46312 [MEDIUM] djvulibre vulnerabilities
djvulibre vulnerabilities
It was discovered that DjVuLibre could be forced to execute a division
by zero in certain instances. A remote attacker could possibly use
this issue to cause applications to stop responding or crash, resulting
in a denial of service. (CVE-2021-46312)
It was discovered that DjVuLibre incorrectly handled certain memory
operations. If a user or automated system were tricked into processing a
specially crafted DjVu file, a remote attacker could cause applications
to stop responding or crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-53367)
OSV
CVE-2025-53367: DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images
osv·2025-07-03·CVSS 8.4
CVE-2025-53367 [HIGH] CVE-2025-53367: DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images
DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.
No detection rules found.
No public exploits indexed.
https://github.blog/security/vulnerability-research/cve-2025-53367-an-exploitable-out-of-bounds-write-in-djvulibrehttps://github.com/github/securitylab/tree/main/SecurityExploits/DjVuLibre/MMRDecoder_scanruns_CVE-2025-53367https://securitylab.github.com/advisories/GHSL-2025-055_DjVuLibre/https://sourceforge.net/p/djvu/djvulibre-git/ci/33f645196593d70bd5e37f55b63886c31c82c3dahttps://www.openwall.com/lists/oss-security/2025/07/03/1http://www.openwall.com/lists/oss-security/2025/07/03/1http://www.openwall.com/lists/oss-security/2025/07/18/3https://lists.debian.org/debian-lts-announce/2025/07/msg00007.htmlhttps://github.blog/security/vulnerability-research/cve-2025-53367-an-exploitable-out-of-bounds-write-in-djvulibre/
2025-07-03
Published