In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24106.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "4.04" } ] } ]