[SECURITY] [DLA 4141-1] poppler security update

Vulnerability Details

Basic Information

Title [SECURITY] [DLA 4141-1] poppler security update
Type debian
Published 2025-04-28T09:42:09
Last Seen 2025-04-28T16:30:05
CVSS Score 6.5 (MEDIUM)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity LOW
Privileges Required NONE
User Interaction REQUIRED
Scope UNCHANGED
Confidentiality Impact NONE
Integrity Impact NONE
Availability Impact HIGH

CVE Information

CVE IDs CVE-2020-36023, CVE-2020-36024, CVE-2022-37050, CVE-2022-37051, CVE-2022-37052, CVE-2022-38349, CVE-2024-56378, CVE-2025-32364, CVE-2025-32365
CWE
Bulletin Family unix

Description

– ————————————————————————-
Debian LTS Advisory DLA-4141-1 [email protected]
https://www.debian.org/lts/security/ Adrian Bunk
April 28, 2025 https://wiki.debian.org/LTS
– ————————————————————————-

Package : poppler
Version : 20.09.0-3.1+deb11u2
CVE ID : CVE-2020-36023 CVE-2020-36024 CVE-2022-37050 CVE-2022-37051
CVE-2022-37052 CVE-2022-38349 CVE-2024-56378 CVE-2025-32364
CVE-2025-32365
Debian Bug : 1091322 1102190 1102191

Multiple vulnerabilities have been fixed in the PDF rendering
library poppler.

CVE-2020-36023

Infinite loop in FoFiType1C::cvtGlyph

CVE-2020-36024

NULL dereference in FoFiType1C::convertToType1

CVE-2022-37050

Crash in PDFDoc::savePageAs

CVE-2022-37051

Crash in the pdfunite tool

CVE-2022-37052

Reachable assert on XRef::add failure

CVE-2022-38349

pdfunite crash on broken files

CVE-2024-56378

Out-of-bounds read in JBIG2Bitmap::combine

CVE-2025-32364

Floating point exception in PSStack::roll

CVE-2025-32365

Out-of-bounds read in JBIG2:Bitmap::combine

For Debian 11 bullseye, these problems have been fixed in version
20.09.0-3.1+deb11u2.

We recommend that you upgrade your poppler packages.

For the detailed security status of poppler please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/poppler

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Impact Assessment

Base Score 6.5
Severity MEDIUM

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.