| Package | poppler |
|---|---|
| Version | 0.48.0-2+deb9u8 (stretch), 0.71.0-5+deb10u5 (buster) |
| Related CVEs | CVE-2025-43718 CVE-2025-43903 CVE-2025-50420 CVE-2025-52885 CVE-2025-52886 CVE-2026-10118 |
- CVE-2025-43718
-
It was discovered that crafted PDF files containing deeply nested structures within the metadata could lead to Denial of Service. (This issue did not affect the poppler version found in Debian stretch.)
- CVE-2025-43903
-
It was discovered signatures with non-empty encapsulated content (typically
adbe.pkcs7.sha1) were not correctly verified, thereby allowing trivial signature forgery. - CVE-2025-50420
-
An infinite recursion issue was discovered in the pdfseparate(1) utility, which may cause denial of service via crafted PDF input file.
- CVE-2025-52885
-
Antonio Morales discovered a use-after-free issue, which may lead to arbitrary code execution via crafted PDF input files. (This issue did not affect the poppler version found in Debian stretch.)
- CVE-2025-52886
-
Kevin Backhouse discovered an integer overflow issue, which may lead to use-after-free via crafted PDF input file.
- CVE-2026-10118
-
An integer overflow issue was discovered in
tilingPatternFill(), which may lead to arbitrary code execution via crafted PDF input files.
For Debian 10 buster, these problems have been fixed in version 0.71.0-5+deb10u5.
For Debian 9 stretch, these problems have been fixed in version 0.48.0-2+deb9u8.
We recommend that you upgrade your poppler packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.