djvulibre ( focal-security; urgency=medium

  * SECURITY UPDATE: Stack overflow
    - debian/patches/CVE-2021-3500.patch: prevent recursion in
      libdjvu/DjVuPort.cpp, libdjvu/DjVuPort.h.
    - CVE-2021-3500
  * SECURITY UPDATE: Out of bounds write
    - debian/patches/CVE-2021-32490.patch: add checks to
    - CVE-2021-32490
  * SECURITY UPDATE: Integer overflow
    - debian/patches/CVE-2021-32491.patch: check for overflow in
    - CVE-2021-32491
  * SECURITY UPDATE: Out of bounds read
    - debian/patches/CVE-2021-32492.patch: check pool in
    - CVE-2021-32492
  * SECURITY UPDATE: Heap buffer overflow
    - debian/patches/CVE-2021-32493.patch: check row size in
    - CVE-2021-32493
  * debian/patches: rename debian-changes to changes.patch to simplify

 -- Marc Deslauriers <email address hidden>  Mon, 17 May 2021 09:18:16 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Original maintainer:
Ubuntu Developers
any all
Medium Urgency

Series Pocket Published Component Section
Focal updates main graphics
Focal security main graphics


File Size SHA-256 Checksum
djvulibre_3.5.27.1.orig.tar.gz 3.1 MiB 77f07de3f1039aa19eba2eb3170d9ce9a0918ba7b704a59cfaf08f42fcc52144
djvulibre_3.5.27.1-14ubuntu0.1.debian.tar.xz 76.2 KiB 792515c49e87fea7eb304507931934d91ef67575f8fa302d58193633f142ec70
djvulibre_3.5.27.1-14ubuntu0.1.dsc 2.4 KiB 1302f741d7ae3a3fab8392fdd5eab085daed0df612dd9bbe4158884931b4ada7

Binary packages built by this source

djview: Transition package, djview3 to djview4

 Ease transition from djview or djview3 to djview4 with this dummy package.

djview3: Transition package, djview3 to djview4

 Ease transition from djview3 to djview4 with this dummy package.

djvulibre-bin: Utilities for the DjVu image format

 Executables including utilities for conversion between DjVu and other

djvulibre-bin-dbgsym: debug symbols for djvulibre-bin
djvulibre-desktop: Desktop support for the DjVu image format

 Miscellaneous files to support the DjVu image format on the desktop.

djvuserve: CGI program for unbundling DjVu files on the fly

 CGI program to convert a bundled multi-page DjVu document into an
 indirect DjVu document on the fly. This provides for efficiently
 browsing large DjVu documents without transferring unnecessary pages.

djvuserve-dbgsym: debug symbols for djvuserve
libdjvulibre-dev: Development files for the DjVu image format

 DjVu image format static library and development files.
 DjVu is a set of compression technologies, a file format, and a
 software platform for the delivery over the Web of digital documents,
 scanned documents, and high resolution images.
 DjVu documents download and display extremely quickly, and look
 exactly the same on all platforms. DjVu can be seen as a superior
 alternative to PDF and Postscript for digital documents, to TIFF (and
 PDF) for scanned documents, to JPEG for photographs and pictures, and
 to GIF for large palettized images. DjVu is the only Web format that
 is practical for distributing high-resolution scanned documents in

libdjvulibre-text: Linguistic support files for libdjvulibre

 Runtime linguistic support files for the libdjvulibre library.

libdjvulibre21: Runtime support for the DjVu image format

 DjVu runtime library.

libdjvulibre21-dbgsym: debug symbols for libdjvulibre21