Alpine: multiple xpdf packages: security update to 4.04-r0

high Tenable Self-Hosted Container Security Plugin ID 427693

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be
changed after the first scan of the image, leading to an unknown integer-related vulnerability in
Stream.cc. (CVE-2022-24106)

- Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. (CVE-2022-24107)

- Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder
(JBIG2Stream::readTextRegionSeg() in JBIG2Stream.cc). Processing a specially crafted PDF file or JBIG2
image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability
described by CVE-2021-30860 (Apple CoreGraphics). (CVE-2022-38171)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-24106

https://security.alpinelinux.org/vuln/CVE-2022-24107

https://security.alpinelinux.org/vuln/CVE-2022-38171

Plugin Details

Severity: High

ID: 427693

Version: Revision 1.5

Type: Local

Published: 5/16/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-38171

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/18/2022

Reference Information

CVE: CVE-2022-24106, CVE-2022-24107, CVE-2022-38171