Loading HuntDB...

CVE-2025-53367

UNKNOWN
Published 2025-07-03T21:07:49.075Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-53367. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.

Available Exploits

No exploits available for this CVE.

Related News

CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre

DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document. The post CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre appeared first on The GitHub …

Github.blog 2025-07-03 20:52
CVE-2025-53367: An exploitable OOB write in DjVuLibre

Posted by Kevin Backhouse on Jul 03DjVuLibre version 3.5.29 was released today. It fixes CVE-2025-53367 (GHSL-2025-055), an out-of-bounds write in the MMRDecoder::scanruns method. The vulnerability could be exploited to gain code execution on a Linux Desktop …

Seclists.org 2025-07-03 20:02

Affected Products

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.

Affected Products (ENISA)

djvunet
djvulibre

ENISA Scoring

CVSS Score (4.0)

8.4
/10
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS Score

0.010
probability

Data provided by ENISA EU Vulnerability Database. Last updated: July 3, 2025

References

Published: 2025-07-03T21:07:49.075Z
Last Modified: 2025-07-03T21:28:52.759Z
Copied to clipboard!