VDB

RHBA-2024%3A8405

RHBA-2024%3A8405 PUBLISHED CVSS 7.800000190734863 HIGH

An integer overflow issue was discovered in Popplers' JBIG2 decoder in the JBIG2Stream::readTextRegionSeg() function in JBIGStream.cc file. This flaw allows an attacker to trick a user into opening a malformed PDF file or JBIG2 image in the application, triggering an integer overflow, which could result in a crash or may lead to the execution of arbitrary code on the target system.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatrhel8/gimp-flatpak@sha256:b8efbf5cbadf96e423583751436b18f84d9d9ff54b47cdb60d863cdfa4a9d88d_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 8)rhel8/gimp-flatpak@sha256:b8efbf5cbadf96e423583751436b18f84d9d9ff54b47cdb60d863cdfa4a9d88d_amd64

Timeline

  • Oct 23, 2024 CVE Published
  • Nov 21, 2025 CVE Updated
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›