Source: poppler
Version: 25.03.0-9
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 25.03.0-5

Hi,

The following vulnerability was published for poppler.

CVE-2025-43718[0]:
| Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption
| and a SIGSEGV via deeply nested structures within the metadata (such
| as GTS_PDFEVersion) of a PDF document, e.g., a regular expression
| for a long pdfsubver string. This occurs in Dict::lookup,
| Catalog::getMetadata, and associated functions in PDFDoc, with deep
| recursion in the regex executor (std::__detail::_Executor).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-43718
    https://www.cve.org/CVERecord?id=CVE-2025-43718
[1] 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to