Vulnerability Name:

CVE-2021-3500 (CCN-204382)

Assigned:2021-06-24
Published:2021-06-24
Updated:2022-03-09
Summary:A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file may lead to application crash and other consequences.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-3500

Source: CCN
Type: DjVuLibre Web site
DjVuLibre

Source: CCN
Type: Red Hat Bugzilla - Bug 1943685
(CVE-2021-3500) - CVE-2021-3500 djvulibre: Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via crafted djvu file

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1943685

Source: XF
Type: UNKNOWN
djvulibre-cve20213500-dos(204382)

Source: DEBIAN
Type: Third Party Advisory
DSA-5032

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-3500

Vulnerable Configuration:Configuration 1:
  • cpe:/a:djvulibre_project:djvulibre:*:*:*:*:*:*:*:* (Version <= 3.5.28)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:11.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:djvulibre_project:djvulibre:3.5.28:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7927
    P
    libdjvulibre-devel-3.5.27-11.11.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7470
    P
    cracklib-2.9.7-11.6.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51567
    P
    Security update for net-snmp (Moderate)
    2022-12-13
    oval:org.opensuse.security:def:95286
    P
    Security update for xen (Important)
    2022-07-29
    oval:org.opensuse.security:def:3307
    P
    ntp-4.2.8p13-85.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94779
    P
    perl-LWP-Protocol-https-6.06-1.24 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94937
    P
    libdjvulibre-devel-3.5.27-11.11.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6055
    P
    Security update for fribidi (Moderate)
    2022-05-25
    oval:org.opensuse.security:def:99466
    P
    (Important)
    2022-03-30
    oval:org.opensuse.security:def:101999
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Critical)
    2022-02-16
    oval:org.opensuse.security:def:112157
    P
    djvulibre-3.5.28-3.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105693
    P
    djvulibre-3.5.28-3.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:97029
    P
    ovmf-2017+git1510945757.b2662641d5-5.22.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:101492
    P
    Security update for libvirt (Moderate)
    2021-08-23
    oval:org.opensuse.security:def:99665
    P
    (Important)
    2021-08-12
    oval:org.opensuse.security:def:99973
    P
    (Important)
    2021-07-15
    oval:org.opensuse.security:def:111577
    P
    Security update for djvulibre (Important)
    2021-07-11
    oval:org.opensuse.security:def:111436
    P
    Security update for djvulibre (Important)
    2021-06-16
    oval:org.opensuse.security:def:118315
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:108665
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:101701
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:68559
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:76212
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:66827
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:109230
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:74291
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:1469
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:97061
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:4134
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:7426
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:67144
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:95851
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:74354
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:4197
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:65223
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:117672
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:108158
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:102564
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:68515
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:75895
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:5738
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:65286
    P
    Security update for djvulibre (Important)
    2021-06-10
    oval:org.opensuse.security:def:10267
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:92126
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:8592
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:99267
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:92914
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:9517
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:70229
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:92317
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:8770
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:69475
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:93067
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:9716
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:70407
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:98881
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:92516
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:8965
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:69657
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:93220
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:10089
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:91931
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:99076
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:92715
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:9335
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:69856
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:32099
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:57450
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:84606
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:23908
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:45699
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:34446
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:59738
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:87395
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:30199
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:55902
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:83286
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:40120
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:5049
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:89393
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:32931
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:57922
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:85644
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:26062
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:125541
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:60269
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:88125
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:31180
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:56022
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:83406
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:41269
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:43251
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:5768
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:33657
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:58754
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:86091
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:29369
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:51896
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:126711
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:38123
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:88438
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:31627
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:57003
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:84148
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:23579
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:44550
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:33915
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:59480
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:86563
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:30079
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:55192
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:82576
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:127108
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:38821
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:89135
    P
    Security update for djvulibre (Important)
    2021-05-31
    BACK
    djvulibre_project djvulibre *
    debian debian linux 10.0
    debian debian linux 11.0
    djvulibre_project djvulibre 3.5.28