Versions mentioned in the description apply to the upstream
Remediation section below for
Debian:9 relevant versions.
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
djvulibre to version 188.8.131.52-7+deb9u1 or higher.