djvulibre 3.5.27.1-8ubuntu0.1 source package in Ubuntu

Changelog

djvulibre (3.5.27.1-8ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: heap-based buffer overread
    - debian/patches/CVE-2019-15142-pre1.patch: fix lengths in
      libdjvu/DjVmDir.cpp, libdjvu/miniexp.cpp, tools/csepdjvu.cpp.
    - debian/patches/CVE-2019-15142.patch: add checks to
      libdjvu/DjVmDir.cpp.
    - CVE-2019-15142
  * SECURITY UPDATE: infinite loop in bitmap reader
    - debian/patches/CVE-2019-15143.patch: check return code in
      libdjvu/GBitmap.cpp, libdjvu/DjVmDir.cpp.
    - CVE-2019-15143
  * SECURITY UPDATE: uncontrolled recursion in sorting
    - debian/patches/CVE-2019-15144.patch: fix logic in
      libdjvu/GContainer.h.
    - CVE-2019-15144
  * SECURITY UPDATE: out of bounds read
    - debian/patches/CVE-2019-15145.patch: check bytes in
      libdjvu/GBitmap.h.
    - CVE-2019-15145
  * SECURITY UPDATE: NULL pointer dereference in DJVU::filter_fv
    - debian/patches/CVE-2019-18804.patch: add extra checks to
      libdjvu/IW44EncodeCodec.cpp, tools/ddjvu.cpp.
    - CVE-2019-18804

 -- Marc Deslauriers <email address hidden>  Wed, 20 Nov 2019 10:26:08 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
djvulibre_3.5.27.1.orig.tar.gz 3.1 MiB 77f07de3f1039aa19eba2eb3170d9ce9a0918ba7b704a59cfaf08f42fcc52144
djvulibre_3.5.27.1-8ubuntu0.1.debian.tar.xz 57.8 KiB f7c443a9710e3ff2bd450a20204dabeeda963ec84ebdf55a1497421e42c9379a
djvulibre_3.5.27.1-8ubuntu0.1.dsc 2.5 KiB 2bdc0712902b8a77e52dfd0abb4ff53af61b6494d804441cd543622dd1a38a02

View changes file

Binary packages built by this source

djview: Transition package, djview3 to djview4

 Ease transition from djview or djview3 to djview4 with this dummy package.

djview3: Transition package, djview3 to djview4

 Ease transition from djview3 to djview4 with this dummy package.

djvulibre-bin: Utilities for the DjVu image format

 Executables including utilities for conversion between DjVu and other
 formats.

djvulibre-bin-dbgsym: debug symbols for djvulibre-bin
djvulibre-desktop: Desktop support for the DjVu image format

 Miscellaneous files to support the DjVu image format on the desktop.

djvuserve: CGI program for unbundling DjVu files on the fly

 CGI program to convert a bundled multi-page DjVu document into an
 indirect DjVu document on the fly. This provides for efficiently
 browsing large DjVu documents without transferring unnecessary pages.

djvuserve-dbgsym: debug symbols for djvuserve
libdjvulibre-dev: Development files for the DjVu image format

 DjVu image format static library and development files.
 .
 DjVu is a set of compression technologies, a file format, and a
 software platform for the delivery over the Web of digital documents,
 scanned documents, and high resolution images.
 .
 DjVu documents download and display extremely quickly, and look
 exactly the same on all platforms. DjVu can be seen as a superior
 alternative to PDF and Postscript for digital documents, to TIFF (and
 PDF) for scanned documents, to JPEG for photographs and pictures, and
 to GIF for large palettized images. DjVu is the only Web format that
 is practical for distributing high-resolution scanned documents in
 color.

libdjvulibre-text: Linguistic support files for libdjvulibre

 Runtime linguistic support files for the libdjvulibre library.

libdjvulibre21: Runtime support for the DjVu image format

 DjVu runtime library.

libdjvulibre21-dbgsym: debug symbols for libdjvulibre21