CVE-2025-53367 – DjVuLibre Out-of-Bounds Write and Read Vulnerability
CVE ID : CVE-2025-53367
Published : July 3, 2025, 9:15 p.m. | 1 hour, 43 minutes ago
Description : DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays within the bounds of the allocated buffer. This can lead to writes beyond the allocated memory, resulting in a heap corruption condition. An out-of-bounds read with pr is also possible for the same reason. This issue has been patched in version 3.5.29.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more…