Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-24106


In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.


Published

2022-08-30T04:15:10.523

Last Modified

2024-11-21T06:49:48.917

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application glyphandcog xpdfreader < 4.04 Yes

References