PT-2025-40292 · Poppler+4 · Poppler+4
Shadowbyte1
·
Published
2025-03-26
·
Updated
2025-11-03
·
CVE-2025-43718
CVSS v3.1
2.9
Low
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Poppler versions 24.06.1 through 25.04.0
Description
The software is susceptible to a stack consumption issue leading to a SIGSEGV signal. This occurs when processing PDF documents containing deeply nested structures within their metadata, such as the
GTS PDFEVersion field. The issue is present in functions including Dict::lookup, Catalog::getMetadata, and related functions within PDFDoc, specifically due to deep recursion in the regular expression executor (std:: detail:: Executor).Recommendations
Update to version 25.04.0 or later.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Poppler
Suse
Ubuntu