ZeroHour

CVE-2022-24106

CVSS 3.1
7.8 high
EPSS
<1%p23
Published
()
Modified
Description

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

Vendors
glyphandcog
Products
xpdfreader
Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.