CVE-2025-32365

CWE-125Out-of-bounds Read8 documents7 sources
Severity
7.1HIGH
EPSS
0.1%
top 76.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 5
Latest updateApr 9

Description

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.5 | Impact: 1.4

Affected Packages3 packages

CVEListV5freedesktop/poppler< 25.04.0
NVDfreedesktop/poppler< 25.04.0
Debianpoppler< 20.09.0-3.1+deb11u2+3

🔴Vulnerability Details

3
GHSA
GHSA-r4rq-7765-p57x: Poppler before 252025-04-07
OSV
CVE-2025-32365: Poppler before 252025-04-05
CVEList
CVE-2025-32365: Poppler before 252025-04-05

📋Vendor Advisories

4
Ubuntu
poppler vulnerabilities2025-04-09
Ubuntu
poppler vulnerabilities2025-04-08
Red Hat
poppler: Out-of-Bounds Read in Poppler2025-04-05
Debian
CVE-2025-32365: poppler - Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads...2025
CVE-2025-32365 (HIGH CVSS 7.1) | Poppler before 25.04.0 allows craft | cvebase.io