CVE-2022-38222: Use After Free
Published Aug 15, 2022
·Updated
There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by sending a crafted PDF file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Affected Software
1 affected component
Xpdfreader Xpdf=4.04
Event History
Aug 15, 2022
CVE Published
via MITRE·04:57 AM
Data Sourced
via MITRE·04:57 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-38222.
2
Where is the use-after-free issue located?
The use-after-free issue is located in JBIG2Stream::close() in the JBIG2Stream.cc file of Xpdf 4.04.
3
How can the use-after-free issue be triggered?
The use-after-free issue can be triggered by sending a crafted PDF file to the pdfimages binary.
4
What are the potential impacts of this vulnerability?
The potential impacts of this vulnerability include Denial of Service and possibly unspecified other impacts.
5
Is there a fix available for this vulnerability?
Please refer to the official Xpdf website or vendor for the fix for this vulnerability.