CVE-2022-38784: Integer Overflow
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-38784?
CVE-2022-38784 is a vulnerability in Poppler prior to and including version 22.08.0 that contains an integer overflow in the JBIG2 decoder, which could lead to a crash or the execution of arbitrary code when processing a specially crafted PDF file or JBIG2 image.
How does CVE-2022-38784 affect Poppler?
CVE-2022-38784 affects Poppler versions prior to and including 22.08.0.
What is the severity of CVE-2022-38784?
The severity of CVE-2022-38784 is high, with a CVSS score of 7.8.
How can CVE-2022-38784 be exploited?
CVE-2022-38784 can be exploited by processing a specially crafted PDF file or JBIG2 image.
What is the remedy for CVE-2022-38784?
The remedy for CVE-2022-38784 is to update Poppler to version 22.08.0-2.1 or 20.09.0-3.1+deb11u1.