|
|
Log in / Subscribe / Register

Ubuntu alert USN-8054-1 (djvulibre)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8054-1] DjVuLibre vulnerabilities
Date:  Mon, 23 Feb 2026 15:17:14 +0000
Message-ID:  <E1vuXgQ-0007RJ-14@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8054-1 February 23, 2026 djvulibre vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in DjVuLibre. Software Description: - djvulibre: DjVu image format library and tools Details: It was discovered that DjVuLibre could be forced to execute a division by zero in certain instances. A remote attacker could possibly use this issue to cause applications to stop responding or crash, resulting in a denial of service. (CVE-2021-46312) It was discovered that DjVuLibre incorrectly handled certain memory operations. If a user or automated system were tricked into processing a specially crafted DjVu file, a remote attacker could cause applications to stop responding or crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2025-53367) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libdjvulibre21 3.5.28-2ubuntu0.24.04.2 Ubuntu 22.04 LTS libdjvulibre21 3.5.28-2ubuntu0.22.04.2 Ubuntu 20.04 LTS libdjvulibre21 3.5.27.1-14ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libdjvulibre21 3.5.27.1-8ubuntu0.4+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libdjvulibre21 3.5.27.1-5ubuntu0.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8054-1 CVE-2021-46312, CVE-2025-53367 Package Information: https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ub... https://launchpad.net/ubuntu/+source/djvulibre/3.5.28-2ub...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmmcbxQACgkQcpJm3tlz hgFN/Q/8DaRjif3Nt89PHeJImoV8YHfMVun3FZZTd9bSn8mGlvvDRdgaZar/G29q F8lWaBog/d5dIurRO0LdkPqak5ibWBq1UxNNNjWtoch+xCux2Kg25gUvfm1PWTTo 81R5gbGG7a38dLS3lGUsYGe3qdBIDQB/l5psyXPnFNab+/EcuwA5HTrdRjecT8ER wh4Uwu6aBzvoGohRvAKSLCSBhvl3e1jBJhAKz29o+cy7KAIVFUy6iMdFcFhei87M BP7+xzUF+nVr4bQg6BTzxoLhdJYr9WWiuM/yMd2ZfWxmOJ/eZHbobNv/vmjp9tWM Vde8wZXiMJ2SuTr5AMXJ8Db0iUcSJj+qfIfYQmVXFCcia5a1PZ4o7aLAOf2O4gy1 23xVRfsRO+2t92ufybM537mKXfKPflfWOaO7hjVJSt/W3lso/yj9AO3WXMlEclNS S6j/tVDU4mlQVDTv405fijVczh5fk972ICq0Cgr4e0lCR0iUTgsfgu5GAFmRlcQT gdkYD9LF+SxWSYxZMOrm8435LwWHGOCl0nmrP3hDD+OgmeDSQLnQECpM+8qNhXju W2g63xBTrqc07/u+P9uF8fcZQRlft4qUax35IPVLXthuCyizMO9+fwHQRBCTuKPr sCMj9RZoMYKzFLWyvm5PLmQuuM3lpAlxA4JQ6EdUqAu+bgeJ66M= =M/mT -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds