PT-2022-4445 · Xpdf+1 · Xpdf+1

Published

2020-11-03

·

Updated

2026-04-13

·

CVE-2022-38171

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Xpdf versions prior to 4.04
Description The issue is related to an integer overflow in the JBIG2 decoder, specifically in the readTextRegionSeg() function (JBIG2Stream.cc). This can be exploited by a remote attacker using a specially crafted PDF file, potentially leading to a crash or the execution of arbitrary code.
Recommendations For versions prior to 4.04, update to version 4.04 or later to resolve the issue. As a temporary workaround, consider avoiding the use of JBIG2 decoded images or PDF files until the update is applied. Restrict access to the JBIG2 decoder module to minimize the risk of exploitation.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2020_4643
ALSA-2021_1881
ALSA-2023_2259
ALSA-2023_2810
ALSA-2024_2979
ALT-PU-2022-3233
ALT-PU-2023-1100
ALT-PU-2024-10474
ALT-PU-2024-10804
ALT-PU-2024-7465
ALT-PU-2025-9424
BDU:2022-05310
BDU:2022-05993
CESA-2023_2810
CVE-2022-38171
DLA-3120-1
DSA-5224-1
ELSA-2023-2259
ELSA-2023-2810
JLSEC-2026-80
JLSEC-2026-81
MGASA-2022-0320
RHSA-2023_2259
RHSA-2023_2810
RLSA-2023_2810
SUSE-SU-2023_0480-1
SUSE-SU-2023_0494-1
SUSE-SU-2023_0495-1
SUSE-SU-2023_0677-1
USN-5606-1
USN-5606-2

Affected Products

Alt Linux
Xpdf