[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-38784Date: (C)2022-09-03   (M)2024-02-09


Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.8CVSS Score :
Exploit Score: 1.8Exploit Score:
Impact Score: 5.9Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: NONEAuthentication:
User Interaction: REQUIREDConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: HIGHAvailability:
Integrity: HIGH 
Availability: HIGH 
  
Reference:
DSA-5224
FEDORA-2022-51b27699ce
FEDORA-2022-f79aa2bae9
FEDORA-2022-f7b375eae8
FEDORA-2022-f8ec1c06a3
FEDORA-2022-fcb3b063a6
GLSA-202209-21
https://lists.debian.org/debian-lts-announce/2022/09/msg00030.html
http://www.openwall.com/lists/oss-security/2022/09/02/11
https://github.com/jeffssh/CVE-2021-30860
https://github.com/zmanion/Vulnerabilities/blob/main/CVE-2022-38171.md
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1261/diffs?commit_id=27354e9d9696ee2bc063910a6c9a6b27c5184a52
https://poppler.freedesktop.org/releases.html
https://www.cve.org/CVERecord?id=CVE-2022-38171

CPE    1
cpe:/a:freedesktop:poppler
CWE    1
CWE-190
OVAL    22
oval:org.secpod.oval:def:86409
oval:org.secpod.oval:def:610111
oval:org.secpod.oval:def:507703
oval:org.secpod.oval:def:507708
...

© SecPod Technologies