USN-7631-1: DjVuLibre vulnerability
USN-7631-1: DjVuLibre vulnerability
Publication date: 9 July 2025
Overview: DjVuLibre could be made to crash or run programs if it opened a specially crafted file.
Packages
djvulibre - DjVu image format library and tools
Details
It was discovered that DjVuLibre incorrectly handled certain memory
operations. If a user or automated system were tricked into processing a
specially crafted DjVu file, a remote attacker could cause applications
to stop responding or crash, resulting in a denial of service, or possibly
execute arbitrary code.
Update instructions
24.04 noble
- libdjvulibre21 – 3.5.28-2ubuntu0.24.04.1

