First published: Sat Apr 05 2025(Updated: )
Last updated 8 April 2025
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Poppler Data | <25.04.0 | |
debian/poppler | <=20.09.0-3.1+deb11u1<=22.12.0-2 | 25.03.0-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32365 is classified as a medium-severity vulnerability due to potential out-of-bounds reads.
To fix CVE-2025-32365, update Poppler to version 25.04.0 or later.
CVE-2025-32365 can lead to information leaks or crashes due to out-of-bounds read operations.
No, if you have upgraded to Poppler version 25.04.0 or later, CVE-2025-32365 is not a risk.
CVE-2025-32365 affects the JBIG2Bitmap::combine function in JBIG2Stream.cc.