-------------------------------------------------------------------------
Debian LTS Advisory DLA-4709-1                [email protected]
https://www.debian.org/lts/security/                       Guilhem Moulin
July 31, 2026                                 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : poppler
Version        : 20.09.0-3.1+deb11u3 22.12.0-2+deb12u3
CVE ID         : CVE-2025-43718 CVE-2025-43903 CVE-2025-50420 CVE-2025-52885
                 CVE-2025-52886 CVE-2026-10118
Debian Bug     : 1103545 1108784 1110463 1117046 1117853 1138708

Multiple vulnerabilities were discovered in poppler, a PDF rendering
library, which could result in signature forgery, information
disclosure, denial of service, or potentially the execution of arbitrary
code.

The following security issues have been identified (and fixed) in poppler
as shipped in Debian bullseye and Debian bookworm.

CVE-2025-43903

    It was discovered signatures with non-empty encapsulated content
    (typically adbe.pkcs7.sha1) were not correctly verified, thereby
    allowing trivial signature forgery.

CVE-2025-50420

    An infinite recursion issue was discovered in the pdfseparate(1)
    utility, which may cause denial of service via crafted PDF input
    file.

CVE-2025-52886

    Kevin Backhouse discovered an integer overflow issue, which may lead
    to use-after-free via crafted PDF input file.

For Debian 12 bookworm, these problems have been fixed in version
22.12.0-2+deb12u3.

In addition, the following issues have been fixed in the poppler version
as shipped in Debian bullseye (for bookworm, these issues were already
fixed in 22.12.0-2+deb12u2 from DSA-6334-1):

CVE-2025-43718

    It was discovered that crafted PDF files containing deeply nested
    structures within the metadata could lead to Denial of Service.

CVE-2025-52885

    Antonio Morales discovered a use-after-free issue, which may lead to
    arbitrary code execution via crafted PDF input files.

CVE-2026-10118

    An integer overflow issue was discovered in tilingPatternFill, which
    may lead to arbitrary code execution via crafted PDF input files.

For Debian 11 bullseye, these problems have been fixed in version
20.09.0-3.1+deb11u3.

We recommend that you upgrade your poppler packages.

For the detailed security status of poppler please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/poppler

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature

Reply via email to