DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Jul 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 03 Jul 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 03 Jul 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV4_0
|
cvssV4_0
|
Thu, 03 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29. | |
Title | DjVuLibre OOB-Write Vulnerability in MMRDecoder | |
Weaknesses | CWE-125 CWE-787 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-03T21:07:49.075Z
Updated: 2025-07-03T21:28:52.759Z
Reserved: 2025-06-27T12:57:16.121Z
Link: CVE-2025-53367

No data.

Status : Received
Published: 2025-07-03T21:15:27.493
Modified: 2025-07-03T22:15:21.140
Link: CVE-2025-53367

No data.