Advisories ยป MGASA-2022-0386

Updated poppler packages fix security vulnerability

Publication date: 23 Oct 2022
Modification date: 23 Oct 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-38784

Description

Poppler prior to and including 22.08.0 contains an integer overflow in the
JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc).
Processing a specially crafted PDF file or JBIG2 image could lead to a
crash or the execution of arbitrary code. This is similar to the
vulnerability described by CVE-2022-38171 in Xpdf. (CVE-2022-38784)
                

References

SRPMS

8/core