PT-2023-25043 · Poppler+7 · Poppler+7

Published

2023-05-15

·

Updated

2026-03-29

·

CVE-2023-34872

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Poppler versions prior to 23.06.0
Description A vulnerability in Outline.cc for Poppler allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open().
Recommendations For versions prior to 23.06.0, update to version 23.06.0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted PDF files until a patch is applied.

Exploit

Fix

DoS

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1256
ALT-PU-2024-1289
BDU:2025-11409
CVE-2023-34872
MGASA-2023-0348
OPENSUSE-SU-2023_4291-1
OPENSUSE-SU-2023_4363-1
ROSA-SA-2023-2303
SUSE-SU-2023:4291-1
SUSE-SU-2023:4363-1
SUSE-SU-2023_4291-1
USN-6273-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Poppler
Red Os
Suse
Ubuntu