CVE-2022-38171
22.08.2022, 19:15
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).Enginsight
Vendor | Product | Version |
---|---|---|
xpdfreader | xpdf | 4.04 |
freedesktop | poppler | 𝑥 < 22.09.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ipe |
| ||||||||||||||||||
texlive-bin |
| ||||||||||||||||||
xpdf |
|
References