A flaw was found in latest djavulibre. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted djvu file may lead to application crash and other consequences. References: https://bugzilla.redhat.com/show_bug.cgi?id=1943424
Created djvulibre tracking bugs for this issue: Affects: epel-7 [bug 1958181] Created mingw-djvulibre tracking bugs for this issue: Affects: fedora-all [bug 1958180]
Created djvulibre tracking bugs for this issue: Affects: fedora-all [bug 1943424]
Acknowledgments: Name: 1vanChen (NSFOCUS Security Team)