CVE-2022-24106
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
30/08/2022
Last modified:
28/10/2022
Description
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:glyphandcog:xpdfreader:*:*:*:*:*:*:*:* | 4.04 (excluding) |
To consult the complete list of CPE names with products and versions, see this page