USN-7426-1: poppler vulnerabilities
Published Apr 8, 2025
·Updated
It was discovered that poppler incorrectly handled memory when opening certain PDF files. An attacker could possibly use this issue to cause poppler to crash, resulting in a denial of service.
Affected Software
16 affected componentsFixes available
All of the following
ubuntu/libpoppler140<24.08.0-1ubuntu0.2
24.08.0-1ubuntu0.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/poppler-utils<24.08.0-1ubuntu0.2
24.08.0-1ubuntu0.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/libpoppler134<24.02.0-1ubuntu9.3
24.02.0-1ubuntu9.3
Ubuntu Ubuntu=24.04
All of the following
ubuntu/poppler-utils<24.02.0-1ubuntu9.3
24.02.0-1ubuntu9.3
Ubuntu Ubuntu=24.04
All of the following
ubuntu/libpoppler118<22.02.0-2ubuntu0.7
22.02.0-2ubuntu0.7
Ubuntu Ubuntu=22.04
All of the following
ubuntu/poppler-utils<22.02.0-2ubuntu0.7
22.02.0-2ubuntu0.7
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libpoppler97<0.86.1-0ubuntu1.6
0.86.1-0ubuntu1.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/poppler-utils<0.86.1-0ubuntu1.6
0.86.1-0ubuntu1.6
Ubuntu Ubuntu=20.04
Event History
Apr 8, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7426-1?
USN-7426-1 has been classified as a denial of service vulnerability.
2
How do I fix USN-7426-1?
To fix USN-7426-1, update to the latest version of the affected packages as specified in the advisory.
3
What software is affected by USN-7426-1?
USN-7426-1 affects the poppler and libpoppler packages on specific versions of Ubuntu.
4
Can USN-7426-1 be exploited remotely?
Yes, an attacker could exploit USN-7426-1 by sending a specially crafted PDF file.
5
What does USN-7426-1 impact specifically?
USN-7426-1 impacts the memory handling of poppler when processing certain PDF files.