216.73.217.22

CVE-2025-53367

· Published 03/07/2025 21:15 · Modified 03/07/2025 22:15

Labels: CVE-2025-53367 2025-07-03CVE-2025-53367CWE-125[email protected]

Essential information

Published
03/07/2025 21:15
Modified
03/07/2025 22:15
Author
Creator
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
djvulibre / djvu cpe:2.3:a:djvulibre:djvu:*:*:*:*:*:*:*:*

References