Loading
Generated remediation guidance and an executive summary. No account required.
Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).
Use CWE-190, Xpdfreader vendor hub and Xpdf product page to widen CVE-2022-38171 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-48545, CVE-2023-3436 and CVE-2024-4568 for nearby disclosures in the same product family.