• 公告ID (KylinSec-SA-2022-2603)

摘要:

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

安全等级: Low

公告ID: KylinSec-SA-2022-2603

发布日期: 2022年11月11日

关联CVE: CVE-2022-38171  

  • 详细介绍

1. 漏洞描述

   

Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2021-30860 (Apple CoreGraphics).

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-38171 KY3.4-4A poppler Unaffected
CVE-2022-38171 KY3.4-5 poppler Unaffected
CVE-2022-38171 KY3.5.1 poppler Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-2602 下一篇:KylinSec-SA-2022-2604