CVE-2022-38171
Published on: Not Yet Published
Last Modified on: 10/27/2022 08:27:00 PM UTC
Certain versions of Poppler from Freedesktop contain the following vulnerability:
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).
- CVE-2022-38171 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Xpdf Security Fixes | www.xpdfreader.com text/html |
![]() |
dl.xpdfreader.com application/gzip |
![]() | |
cve-website | www.cve.org text/html |
![]() |
Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution | googleprojectzero.blogspot.com text/html |
![]() |
oss-security - JBIG2 integer overflow fixed in Xpdf 4.04, Poppler 22.09.0 | www.openwall.com text/html |
![]() |
CVE-2022-38171 notes · GitHub | gist.github.com text/html |
![]() |
404 Not Found | dl.xpdfreader.com text/html Inactive LinkNot Archived |
![]() |
Vulnerabilities/CVE-2022-38171.md at main · zmanion/Vulnerabilities · GitHub | github.com text/html |
![]() |
GitHub - jeffssh/CVE-2021-30860: Collection of materials relating to FORCEDENTRY, will eventually delete this repo and migrate the materials to my main exploit repo once finished | github.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBI…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Freedesktop | Poppler | All | All | All | All |
Application | Xpdfreader | Xpdf | 4.04 | All | All | All |
- cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*:
- cpe:2.3:a:xpdfreader:xpdf:4.04:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-38171 : Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder JBIG2Stream::readSym… twitter.com/i/web/status/1… | 2022-08-22 19:05:51 |
![]() |
[email protected] changed textproc/xpdf: Security fix for CVE-2022-38171. See: gist.github.com/zmanion/b2ed0d… | 2022-08-24 08:25:22 |
![]() |
[email protected] changed print/poppler: Fix for CVE-2022-38171 (similar to the one [email protected] added to xpdf). (No update to a new… twitter.com/i/web/status/1… | 2022-08-27 20:55:22 |
![]() |
CVE-2022-38171 | 2022-08-22 20:38:22 |