CVE-2022-24106: Integer Overflow
Published Aug 30, 2022
·Updated
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
Affected Software
1 affected component
Glyphandcog Xpdfreader<4.04
Event History
Aug 30, 2022
CVE Published
via MITRE·03:05 AM
Data Sourced
via MITRE·03:05 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-24106?
CVE-2022-24106 is categorized as an unknown severity vulnerability.
2
How do I fix CVE-2022-24106?
To mitigate CVE-2022-24106, upgrade Xpdf to version 4.04 or later.
3
What software is affected by CVE-2022-24106?
CVE-2022-24106 affects Xpdf versions prior to 4.04.
4
What does CVE-2022-24106 exploit?
CVE-2022-24106 exploits an issue with the DCT (JPEG) decoder's handling of the 'interleaved' flag.
5
Is CVE-2022-24106 being actively exploited?
There is currently no public information indicating that CVE-2022-24106 is being actively exploited.