The rowisempty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
{
"binaries": [
{
"binary_name": "libminidjvu-dev",
"binary_version": "0.8.svn.2010.05.06+dfsg-5build1"
},
{
"binary_name": "libminidjvu0",
"binary_version": "0.8.svn.2010.05.06+dfsg-5build1"
},
{
"binary_name": "minidjvu",
"binary_version": "0.8.svn.2010.05.06+dfsg-5build1"
}
]
}{
"binaries": [
{
"binary_name": "libminidjvu-dev",
"binary_version": "0.8.svn.2010.05.06+dfsg-6build1"
},
{
"binary_name": "libminidjvu0",
"binary_version": "0.8.svn.2010.05.06+dfsg-6build1"
},
{
"binary_name": "minidjvu",
"binary_version": "0.8.svn.2010.05.06+dfsg-6build1"
}
]
}{
"binaries": [
{
"binary_name": "libminidjvu-dev",
"binary_version": "0.8.svn.2010.05.06+dfsg-6build1"
},
{
"binary_name": "libminidjvu0",
"binary_version": "0.8.svn.2010.05.06+dfsg-6build1"
},
{
"binary_name": "minidjvu",
"binary_version": "0.8.svn.2010.05.06+dfsg-6build1"
}
]
}{
"binaries": [
{
"binary_name": "libminidjvu-dev",
"binary_version": "0.8.svn.2010.05.06+dfsg-7build1"
},
{
"binary_name": "libminidjvu0t64",
"binary_version": "0.8.svn.2010.05.06+dfsg-7build1"
},
{
"binary_name": "minidjvu",
"binary_version": "0.8.svn.2010.05.06+dfsg-7build1"
}
]
}{
"binaries": [
{
"binary_name": "libminidjvu-dev",
"binary_version": "0.8.svn.2010.05.06+dfsg-7build1"
},
{
"binary_name": "libminidjvu0t64",
"binary_version": "0.8.svn.2010.05.06+dfsg-7build1"
},
{
"binary_name": "minidjvu",
"binary_version": "0.8.svn.2010.05.06+dfsg-7build1"
}
]
}