CVE-2022-24106

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
30/08/2022
Last modified:
28/10/2022

Description

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:glyphandcog:xpdfreader:*:*:*:*:*:*:*:* 4.04 (excluding)