djvulibre 3.5.27.1-8ubuntu0.3 source package in Ubuntu

Changelog

djvulibre (3.5.27.1-8ubuntu0.3) bionic-security; urgency=medium

  * SECURITY UPDATE: Stack overflow
    - debian/patches/CVE-2021-3500.patch: prevent recursion in
      libdjvu/DjVuPort.cpp, libdjvu/DjVuPort.h.
    - CVE-2021-3500
  * SECURITY UPDATE: Out of bounds write
    - debian/patches/CVE-2021-32490.patch: add checks to
      libdjvu/IW44Image.cpp.
    - CVE-2021-32490
  * SECURITY UPDATE: Integer overflow
    - debian/patches/CVE-2021-32491.patch: check for overflow in
      tools/ddjvu.cpp.
    - CVE-2021-32491
  * SECURITY UPDATE: Out of bounds read
    - debian/patches/CVE-2021-32492.patch: check pool in
      libdjvu/DataPool.cpp.
    - CVE-2021-32492
  * SECURITY UPDATE: Heap buffer overflow
    - debian/patches/CVE-2021-32493.patch: check row size in
      libdjvu/GBitmap.cpp.
    - CVE-2021-32493
  * debian/patches: rename debian-changes to changes.patch to simplify
    maintenance.

 -- Marc Deslauriers <email address hidden>  Mon, 17 May 2021 09:19:55 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Bionic
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
djvulibre_3.5.27.1.orig.tar.gz 3.1 MiB 77f07de3f1039aa19eba2eb3170d9ce9a0918ba7b704a59cfaf08f42fcc52144
djvulibre_3.5.27.1-8ubuntu0.3.debian.tar.xz 59.7 KiB c1b1240638b507d6a37642e5a2cdede979e9ddfba9ced11818da84addd9f3044
djvulibre_3.5.27.1-8ubuntu0.3.dsc 2.5 KiB acd20cfc3dbb8913a69e946b184aa2fddd9de628bd7bc256d0cdfb068d58c3e5

View changes file

Binary packages built by this source

djview: Transition package, djview3 to djview4

 Ease transition from djview or djview3 to djview4 with this dummy package.

djview3: Transition package, djview3 to djview4

 Ease transition from djview3 to djview4 with this dummy package.

djvulibre-bin: Utilities for the DjVu image format

 Executables including utilities for conversion between DjVu and other
 formats.

djvulibre-bin-dbgsym: debug symbols for djvulibre-bin
djvulibre-desktop: Desktop support for the DjVu image format

 Miscellaneous files to support the DjVu image format on the desktop.

djvuserve: CGI program for unbundling DjVu files on the fly

 CGI program to convert a bundled multi-page DjVu document into an
 indirect DjVu document on the fly. This provides for efficiently
 browsing large DjVu documents without transferring unnecessary pages.

djvuserve-dbgsym: debug symbols for djvuserve
libdjvulibre-dev: Development files for the DjVu image format

 DjVu image format static library and development files.
 .
 DjVu is a set of compression technologies, a file format, and a
 software platform for the delivery over the Web of digital documents,
 scanned documents, and high resolution images.
 .
 DjVu documents download and display extremely quickly, and look
 exactly the same on all platforms. DjVu can be seen as a superior
 alternative to PDF and Postscript for digital documents, to TIFF (and
 PDF) for scanned documents, to JPEG for photographs and pictures, and
 to GIF for large palettized images. DjVu is the only Web format that
 is practical for distributing high-resolution scanned documents in
 color.

libdjvulibre-text: Linguistic support files for libdjvulibre

 Runtime linguistic support files for the libdjvulibre library.

libdjvulibre21: Runtime support for the DjVu image format

 DjVu runtime library.

libdjvulibre21-dbgsym: debug symbols for libdjvulibre21