PT-2022-16467 · Xpdf+4 · Xpdf+4

Shin Ando

·

Published

2022-05-15

·

Updated

2026-01-29

·

CVE-2022-24106

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xpdf versions prior to 4.04
Description The issue is related to the DCT (JPEG) decoder in Xpdf, which incorrectly allows the interleaved flag to be changed after the first scan of the image. This leads to an unknown integer-related issue in Stream.cc.
Recommendations For versions prior to 4.04, update to version 4.04 or later to resolve the issue.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1867
ALT-PU-2022-2449
CVE-2022-24106
ECHO-9BF0-CD5C-D541
MGASA-2022-0320
USN-7985-1

Affected Products

Alt Linux
Debian
Linuxmint
Ubuntu
Xpdf