CVE-2025-53367 was announced here: https://www.openwall.com/lists/oss-security/2025/07/03/1 Fix: https://sourceforge.net/p/djvu/djvulibre-git/ci/33f645196593d70bd5e37f55b63886c31c82c3da/
Status comment: (none) => Fixed upstream in 3.5.29 and patch available from upstreamSource RPM: (none) => djvulibre-3.5.28-7.mga10.src.rpm, djvulibre-3.5.28-5.1.mga9.src.rpmCVE: (none) => CVE-2025-53367Whiteboard: (none) => MGA9TOO
No registered maintainer, assigning to all.
CC: (none) => marja11Assignee: bugsquad => pkg-bugs
Ubuntu has issued an advisory on July 9: https://ubuntu.com/security/notices/USN-7631-1
Assignee: pkg-bugs => j.alberto.vc
David Fix this in Cauldron
Version: Cauldron => 9Whiteboard: MGA9TOO => (none)Source RPM: djvulibre-3.5.28-7.mga10.src.rpm, djvulibre-3.5.28-5.1.mga9.src.rpm => djvulibre-3.5.28-5.1.mga9.src.rpm
RPMS: djvulibre-3.5.29-1.mga9 lib(64)djvulibre-devel-3.5.29-1.mga9 lib(64)djvulibre21-3.5.29-1.mga9 SRPM: djvulibre-3.5.29-1.mga9
Assignee: j.alberto.vc => qa-bugs
Source RPM: djvulibre-3.5.28-5.1.mga9.src.rpm => djvulibre-3.5.28-5.1.mga9
RH x86_64 installing djvulibre-3.5.29-1.mga9.x86_64.rpm lib64djvulibre21-3.5.29-1.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: lib64djvulibre21 ################################################################################################## 2/2: djvulibre ################################################################################################## 1/2: removing djvulibre-3.5.28-5.1.mga9.x86_64 ################################################################################################## 2/2: removing lib64djvulibre21-3.5.28-5.1.mga9.x86_64 ################################################################################################## strace qpdfview, once I open a .djv file shows openat(AT_FDCWD, "/lib64/libdjvulibre.so.21", O_RDONLY|O_CLOEXEC) = 17 Works OK strace okular file.djv , shows openat(AT_FDCWD, "/lib64/libdjvulibre.so.21", O_RDONLY|O_CLOEXEC) = 21 Works OK
MGA9-64 server Plasma Wayland on Compaq H000SB. No istallation issues. Ref bug 33221 for testing, installed pdf2djvu and run: $ pdf2djvu handleidingVM.pdf > testfjvu.djv The pdf is a 12 page document with lots of screenshots in it. The resulting djv file opens OK in okular, contents is OK. Good to go.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA9-64-OK
Keywords: (none) => advisory
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0209.html
Status: NEW => RESOLVEDResolution: (none) => FIXED