CVE-2022-24106

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:glyphandcog:xpdfreader:*:*:*:*:*:*:*:*

History

18 Oct 2022, 19:15

Type Values Removed Values Added
References
  • {'url': 'https://dl.xpdfreader.com/old/xpdf-4.04.tar.gz', 'name': 'https://dl.xpdfreader.com/old/xpdf-4.04.tar.gz', 'tags': ['Broken Link'], 'refsource': 'CONFIRM'}
  • {'url': 'http://www.xpdfreader.com/old-versions.html', 'name': 'http://www.xpdfreader.com/old-versions.html', 'tags': ['Product', 'Vendor Advisory'], 'refsource': 'CONFIRM'}

01 Sep 2022, 20:46

Type Values Removed Values Added
CWE CWE-190
First Time Glyphandcog
Glyphandcog xpdfreader
CPE cpe:2.3:a:glyphandcog:xpdfreader:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (CONFIRM) http://www.xpdfreader.com/security-fixes.html - (CONFIRM) http://www.xpdfreader.com/security-fixes.html - Vendor Advisory
References (CONFIRM) https://dl.xpdfreader.com/xpdf-4.04.tar.gz - (CONFIRM) https://dl.xpdfreader.com/xpdf-4.04.tar.gz - Product, Vendor Advisory
References (CONFIRM) https://dl.xpdfreader.com/old/xpdf-4.04.tar.gz - (CONFIRM) https://dl.xpdfreader.com/old/xpdf-4.04.tar.gz - Broken Link
References (CONFIRM) http://www.xpdfreader.com/old-versions.html - (CONFIRM) http://www.xpdfreader.com/old-versions.html - Product, Vendor Advisory

30 Aug 2022, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-30 04:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-24106

Mitre link : CVE-2022-24106

CVE.ORG link : CVE-2022-24106


JSON object : View

Products Affected

glyphandcog

  • xpdfreader
CWE
CWE-190

Integer Overflow or Wraparound