Description
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.5 | Impact: 1.4Attack Vector: Local
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: Low
Affected Packages3 packages
▶Debianpoppler< 20.09.0-3.1+deb11u2+3 🔴Vulnerability Details
3GHSAGHSA-r4rq-7765-p57x: Poppler before 25↗2025-04-07 ▶ OSVCVE-2025-32365: Poppler before 25↗2025-04-05 ▶ CVEListCVE-2025-32365: Poppler before 25↗2025-04-05 ▶ 📋Vendor Advisories
4Ubuntupoppler vulnerabilities↗2025-04-09 ▶ Ubuntupoppler vulnerabilities↗2025-04-08 ▶ Red Hatpoppler: Out-of-Bounds Read in Poppler↗2025-04-05 ▶ DebianCVE-2025-32365: poppler - Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads...↗2025 ▶