CVE-2025-32365: High severity Poppler Poppler vulnerability
Last updated 8 April 2025
Other sources
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
— NVD
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32365?
CVE-2025-32365 is classified as a medium-severity vulnerability due to potential out-of-bounds reads.
How do I fix CVE-2025-32365?
To fix CVE-2025-32365, update Poppler to version 25.04.0 or later.
What vulnerabilities can CVE-2025-32365 lead to?
CVE-2025-32365 can lead to information leaks or crashes due to out-of-bounds read operations.
Is CVE-2025-32365 still a risk if I have upgraded to the latest version of Poppler?
No, if you have upgraded to Poppler version 25.04.0 or later, CVE-2025-32365 is not a risk.
What specific function is affected by CVE-2025-32365?
CVE-2025-32365 affects the JBIG2Bitmap::combine function in JBIG2Stream.cc.