VYPR

rpm package

suse/poppler&distro=SUSE Linux Enterprise Server LTSS Extended Security 12 SP5

pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Vulnerabilities (7)

  • CVE-2025-11896LowOct 16, 2025
    affected < 0.43.0-16.70.1fixed 0.43.0-16.70.1

    In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.

  • CVE-2025-50420Aug 4, 2025
    affected < 0.43.0-16.64.1fixed 0.43.0-16.64.1

    An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. This can lead to a Denial of Service (DoS).

  • CVE-2025-52886Jul 2, 2025
    affected < 0.43.0-16.58.2fixed 0.43.0-16.58.2

    Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

  • CVE-2025-32365Apr 5, 2025
    affected < 0.43.0-16.55.1fixed 0.43.0-16.55.1

    Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

  • CVE-2025-32364Apr 5, 2025
    affected < 0.43.0-16.55.1fixed 0.43.0-16.55.1

    A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

  • CVE-2025-3154LowApr 2, 2025
    affected < 0.43.0-16.67.1fixed 0.43.0-16.67.1

    Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.

  • CVE-2024-56378Dec 22, 2024
    affected < 0.43.0-16.52.1fixed 0.43.0-16.52.1

    libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.