CVE-2022-24106

NameCVE-2022-24106
DescriptionIn Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1021669

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
poppler (PTS)buster0.71.0-5vulnerable (unimportant)
buster (security)0.71.0-5+deb10u3vulnerable (unimportant)
bullseye (security), bullseye20.09.0-3.1+deb11u1vulnerable (unimportant)
bookworm, trixie22.12.0-2vulnerable (unimportant)
sid22.12.0-2.2vulnerable (unimportant)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
popplersource(unstable)(unfixed)unimportant1021669

Notes

https://gitlab.freedesktop.org/poppler/poppler/-/issues/1297
Code only compiled with -DENABLE_DCTDECODER=unmaintained

Search for package or bug name: Reporting problems