[Git][security-tracker-team/security-tracker][master] Reserve DLA-4709-1 for poppler
Guilhem Moulin (@guilhem)
guilhem at debian.org
Fri Jul 31 23:07:04 BST 2026
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker
Commits:
56abc549 by Guilhem Moulin at 2026-07-31T23:40:09+02:00
Reserve DLA-4709-1 for poppler
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -49732,6 +49732,7 @@ CVE-2026-10197 (A vulnerability was detected in Assimp up to 6.0.4. Affected is
CVE-2026-10118 (A flaw was found in Poppler's Splash backend. A remote attacker could ...)
{DSA-6334-1}
- poppler 26.01.0-4.1 (bug #1138708)
+ [bullseye] - poppler 20.09.0-3.1+deb11u3
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/commit/8352264766652b98336e92359a70b3161a9ab97a
CVE-2026-0826 (In certain scenarios when the admin has enabled Interactive Connectivi ...)
@@ -159014,7 +159015,7 @@ CVE-2025-54654 (Permission control vulnerability in the Gallery module. Successf
CVE-2025-52885 (Poppler ia a library for rendering PDF files, and examining or modifyi ...)
{DSA-6334-1}
- poppler 25.03.0-11.1 (bug #1117853)
- [bullseye] - poppler <postponed> (Minor issue; only affeccts CLI tools run with non-default CLI options)
+ [bullseye] - poppler 20.09.0-3.1+deb11u3
NOTE: https://securitylab.github.com/advisories/GHSL-2025-042_poppler/
NOTE: https://github.com/github/securitylab/tree/main/SecurityExploits/freedesktop/poppler-CVE-2025-52885
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1884
@@ -163097,7 +163098,7 @@ CVE-2025-43826 (Stored cross-site scripting (XSS) vulnerabilities in Web Content
CVE-2025-43718 (Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption a ...)
{DSA-6334-1}
- poppler 25.03.0-10 (bug #1117046)
- [bullseye] - poppler <postponed> (minor issue)
+ [bullseye] - poppler 20.09.0-3.1+deb11u3
NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408 (poppler-25.04.0)
CVE-2025-41421 (Improper handling of symbolic links in the TeamViewer Full Client and ...)
NOT-FOR-US: TeamViewer
@@ -184236,8 +184237,6 @@ CVE-2025-50422 (Cairo through 1.18.4, as used in Poppler through 25.08.0, has an
CVE-2025-50420 (An issue in the pdfseparate utility of freedesktop poppler v25.04.0 al ...)
- poppler 25.03.0-6 (bug #1110463)
[trixie] - poppler 25.03.0-5+deb13u2
- [bookworm] - poppler <no-dsa> (Minor issue)
- [bullseye] - poppler <postponed> (minor issue; Local DoS)
NOTE: https://github.com/Landw-hub/CVE-2025-50420
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1613
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1849
@@ -194199,8 +194198,6 @@ CVE-2025-52891 (ModSecurity is an open source, cross platform web application fi
NOTE: Fixed by: https://github.com/owasp-modsecurity/ModSecurity/commit/8879413abf507b1921f6feb292ee91e0f0064b01 (v2.9.11)
CVE-2025-52886 (Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std ...)
- poppler 25.03.0-5 (bug #1108784)
- [bookworm] - poppler <no-dsa> (Minor issue)
- [bullseye] - poppler <postponed> (Minor issue)
NOTE: https://securitylab.github.com/advisories/GHSL-2025-054_poppler/
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1581
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1828
@@ -216463,8 +216460,6 @@ CVE-2025-2866 (Improper Verification of Cryptographic Signature vulnerability in
NOTE: Introduced by [2/2] https://git.libreoffice.org/core/+/e58ed17e35989350afe3e9fd77b24515df782eac%5E! (5.4.0.0.alpha0+)
CVE-2025-43903 (NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the ...)
- poppler 25.03.0-4 (bug #1103545)
- [bookworm] - poppler <no-dsa> (Minor issue)
- [bullseye] - poppler <postponed> (Minor issue)
NOTE: Introduced with: https://gitlab.freedesktop.org/poppler/poppler/-/commit/c7c0207b1cfe49a4353d6cda93dbebef4508138f (poppler-0.42.0)
NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/f1b9c830f145a0042e853d6462b2f9ca4016c669 (poppler-25.04.0)
CVE-2025-3795 (A vulnerability was found in DaiCuo 1.3.13. It has been rated as probl ...)
@@ -304040,6 +304035,7 @@ CVE-2024-6240 (Improper privilege management vulnerability in Parallels Desktop
NOT-FOR-US: Parallels Desktop
CVE-2024-6239 (A flaw was found in the Poppler's Pdfinfo utility. This issue occurs w ...)
- poppler 24.08.0-2 (unimportant; bug #1074146)
+ [bookworm] - poppler 22.12.0-2+deb12u3
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2293594
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/issues/1489
NOTE: Fixed by: https://gitlab.freedesktop.org/poppler/poppler/-/commit/0554731052d1a97745cb179ab0d45620589dd9c4 (poppler-24.07.0)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[31 Jul 2026] DLA-4709-1 poppler - security update
+ {CVE-2025-43903 CVE-2025-50420 CVE-2025-52886}
+ [bullseye] - poppler 20.09.0-3.1+deb11u3
+ [bookworm] - poppler 22.12.0-2+deb12u3
[31 Jul 2026] DLA-4708-1 python-authlib - security update
{CVE-2026-44681}
[bullseye] - python-authlib 0.15.4-1+deb11u4
=====================================
data/dla-needed.txt
=====================================
@@ -647,9 +647,6 @@ phpseclib/bullseye (Utkarsh)
NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
NOTE: 20260720: will get back to this after releasing squid. (utkarsh)
--
-poppler/bullseye (guilhem)
- NOTE: 20260605: Added by Front-Desk (pochu)
---
proftpd-dfsg
NOTE: 20260511: Added by Beuc for maintainer (Hilmar Preuße)
NOTE: 20260511: https://lists.debian.org/debian-lts/2026/05/msg00015.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56abc549b05da7879415ec928a6eac1464c2a039
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/56abc549b05da7879415ec928a6eac1464c2a039
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/2be6c24a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list