[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2025-43718/poppler: Reference commit introducing the issue
Guilhem Moulin (@guilhem)
guilhem at debian.org
Sat Aug 1 14:43:59 BST 2026
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker
Commits:
afbabb2f by Guilhem Moulin at 2026-08-01T14:49:45+02:00
CVE-2025-43718/poppler: Reference commit introducing the issue
- - - - -
703ef968 by Guilhem Moulin at 2026-08-01T15:23:17+02:00
CVE-2025-52885/poppler: Reference commit introducing the issue
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -159577,6 +159577,7 @@ CVE-2025-52885 (Poppler ia a library for rendering PDF files, and examining or m
NOTE: https://github.com/github/securitylab/tree/main/SecurityExploits/freedesktop/poppler-CVE-2025-52885
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1884
NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/4ce27cc826bf90cc8dbbd8a8c87bd913cccd7ec0 (poppler-25.10.0)
+ NOTE: Introduced with: https://gitlab.freedesktop.org/poppler/poppler/-/commit/321538259a9c79a99ce846a6ea2d94dd7fa56f61 (poppler-0.63.0)
CVE-2025-52647 (The BigFix WebUI application responds with HOST information from the H ...)
NOT-FOR-US: HCL
CVE-2025-31718 (In modem, there is a possible system crash due to improper input valid ...)
@@ -163657,6 +163658,7 @@ CVE-2025-43718 (Poppler 24.06.1 through 25.x before 25.04.0 allows stack consump
- poppler 25.03.0-10 (bug #1117046)
[bullseye] - poppler 20.09.0-3.1+deb11u3
NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408 (poppler-25.04.0)
+ NOTE: Introduced with: https://gitlab.freedesktop.org/poppler/poppler/-/commit/98d1b3dcc2c0530c12fb4422067c529ab375c680 (poppler-0.69.0)
CVE-2025-41421 (Improper handling of symbolic links in the TeamViewer Full Client and ...)
NOT-FOR-US: TeamViewer
CVE-2025-40648 (Stored Cross-Site Scripting (XSS) vulnerability in Issabel v5.0.0, con ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/99bace2dc6972a072f1785913f014d7ad082d5e3...703ef9680a75e15e953542066380a2ba10bfdd57
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/99bace2dc6972a072f1785913f014d7ad082d5e3...703ef9680a75e15e953542066380a2ba10bfdd57
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/b947c472/attachment.htm>
More information about the debian-security-tracker-commits
mailing list