VulnerabilityModified
CVE-2022-24106
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
HIGH 7.8EPSS 0.31%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- glyphandcog/xpdfreader
- Source
- cve@mitre.org
References
- http://www.xpdfreader.com/security-fixes.htmlVendor Advisory
- https://dl.xpdfreader.com/xpdf-4.04.tar.gzProduct, Vendor Advisory
- http://www.xpdfreader.com/security-fixes.htmlVendor Advisory
- https://dl.xpdfreader.com/xpdf-4.04.tar.gzProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.