VDB
RHBA-2024%3A8405
RHBA-2024%3A8405
PUBLISHED
CVSS 7.800000190734863 HIGH
An integer overflow issue was discovered in Popplers' JBIG2 decoder in the JBIG2Stream::readTextRegionSeg() function in JBIGStream.cc file. This flaw allows an attacker to trick a user into opening a malformed PDF file or JBIG2 image in the application, triggering an integer overflow, which could result in a crash or may lead to the execution of arbitrary code on the target system.
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhel8/gimp-flatpak@sha256:b8efbf5cbadf96e423583751436b18f84d9d9ff54b47cdb60d863cdfa4a9d88d_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 8) | rhel8/gimp-flatpak@sha256:b8efbf5cbadf96e423583751436b18f84d9d9ff54b47cdb60d863cdfa4a9d88d_amd64 |
Timeline
- Oct 23, 2024 CVE Published
- Nov 21, 2025 CVE Updated
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2024:8405 advisory
- https://catalog.redhat.com/software/containers/search advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2124527 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2173917 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2231520 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2234527 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2234528 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2240059 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2249755 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2283508 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_8405.json advisory
- https://access.redhat.com/security/cve/CVE-2022-38784 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-38784 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-38784 advisory
- https://www.openwall.com/lists/oss-security/2022/09/02/11 advisory