Back to Database
Status published
High
CVE-2019-18804
DjVuLibre 3.5.27 has a NULL pointer dereference in the function...
Vulnerability Description
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-18804
Credits & Attribution
No credits recorded in the NVD database.
References
- https://sourceforge.net/p/djvu/bugs/309/
- https://github.com/TeamSeri0us/pocs/blob/master/djvulibre/DJVU__filter_fv%40IW44EncodeCodec.cpp_499-43___SEGV_UNKNOW.md
- https://lists.debian.org/debian-lts-announce/2019/11/msg00004.html
- https://usn.ubuntu.com/4198-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUEME45HVGTMDOYODAZYQOGWSZ2CEFWZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JO65AWU7LEWNF6DDCZPRFTR2ZPP5XK6L/
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00068.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00069.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYPWP5T7TSUNZV4UEIRRCTVWO6VBZWJV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SWT7E7BMWV5T33AMU6OGDPPTPIGCFFZF/
- https://lists.debian.org/debian-lts-announce/2021/05/msg00022.html
- https://www.debian.org/security/2021/dsa-5032
More from djvulibre project
View All →CVE-2021-46312
An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows...
Medium
6.5
CVE-2021-46310
An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows...
Medium
6.5
CVE-2019-15145
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application...
Medium
5.5
CVE-2019-15144
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers...
Medium
5.5
CVE-2019-15143
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to...
Medium
5.5
Affected Vendor
djvulibre project
View all reports →Affected Software
djvulibre, debian linux, fedora, ubuntu linux, leap
Vulnerable Versions:
3.5.27, 8.0, 9.0, 10.0, 11.0, 30, 31, 16.04, 18.04, 19.04, 19.10, 15.0, 15.1
Timeline
Official Publish:
November 7th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.