VYPR
High severity7.8NVD Advisory· Published Aug 22, 2022· Updated Jun 17, 2026

CVE-2022-38171

CVE-2022-38171

Description

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
    Range: <22.09.0
  • Xpdf/Xpdf2 versions
    cpe:2.3:a:xpdfreader:xpdf:4.04:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:xpdfreader:xpdf:4.04:*:*:*:*:*:*:*
    • (no CPE)
  • Range: <4.04

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.