Bug#1117046: poppler: CVE-2025-43718

Salvatore Bonaccorso carnil at debian.org
Thu Oct 2 20:30:59 BST 2025


Source: poppler
Version: 25.03.0-9
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Control: found -1 25.03.0-5

Hi,

The following vulnerability was published for poppler.

CVE-2025-43718[0]:
| Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption
| and a SIGSEGV via deeply nested structures within the metadata (such
| as GTS_PDFEVersion) of a PDF document, e.g., a regular expression
| for a long pdfsubver string. This occurs in Dict::lookup,
| Catalog::getMetadata, and associated functions in PDFDoc, with deep
| recursion in the regex executor (std::__detail::_Executor).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-43718
    https://www.cve.org/CVERecord?id=CVE-2025-43718
[1] https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Pkg-freedesktop-maintainers mailing list