In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
https://www.debian.org/security/2021/dsa-5032
https://usn.ubuntu.com/4198-1/
https://sourceforge.net/p/djvu/djvulibre-git/ci/b1f4e1b2187d9e5010cd01ceccf20b4a11ce723f/
https://sourceforge.net/p/djvu/bugs/297/
https://security.gentoo.org/glsa/202007-36
https://lists.debian.org/debian-lts-announce/2021/05/msg00022.html
https://lists.debian.org/debian-lts-announce/2019/08/msg00036.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00087.html
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00086.html