Bug#1117046: poppler: CVE-2025-43718
Salvatore Bonaccorso
carnil at debian.org
Thu Oct 2 20:30:59 BST 2025
Source: poppler
Version: 25.03.0-9
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Control: found -1 25.03.0-5
Hi,
The following vulnerability was published for poppler.
CVE-2025-43718[0]:
| Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption
| and a SIGSEGV via deeply nested structures within the metadata (such
| as GTS_PDFEVersion) of a PDF document, e.g., a regular expression
| for a long pdfsubver string. This occurs in Dict::lookup,
| Catalog::getMetadata, and associated functions in PDFDoc, with deep
| recursion in the regex executor (std::__detail::_Executor).
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-43718
https://www.cve.org/CVERecord?id=CVE-2025-43718
[1] https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the Pkg-freedesktop-maintainers
mailing list