First published: Mon Apr 18 2022(Updated: )
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Glyph & Cog XpdfReader | <4.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24106 is categorized as an unknown severity vulnerability.
To mitigate CVE-2022-24106, upgrade Xpdf to version 4.04 or later.
CVE-2022-24106 affects Xpdf versions prior to 4.04.
CVE-2022-24106 exploits an issue with the DCT (JPEG) decoder's handling of the 'interleaved' flag.
There is currently no public information indicating that CVE-2022-24106 is being actively exploited.