SUSE-SU-2025:3900-1
Dashboard / Vulnerabilities / SUSE-SU-2025:3900-1
SUSE-SU-2025:3900-1
Summary: Security update for poppler
Details: This update for poppler fixes the following issues: - CVE-2025-43718: Fixed uncontrolled recursion in the regex-based metadata parser when processing specially crafted PDF files allows for stack exhaustion and denial of service (bsc#1250908). - CVE-2025-52885: Fixed raw pointers can lead to dangling pointers when the vector is resized (bsc#1251940).
References: https://www.suse.com/support/update/announcement/2025/suse-su-20253900-1/, https://bugzilla.suse.com/1250908, https://bugzilla.suse.com/1251940, https://www.suse.com/security/cve/CVE-2025-43718, https://www.suse.com/security/cve/CVE-2025-52885
Affected packages
Package
Name: poppler
Purl: pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS
Affected ranges
Type: ECOSYSTEM
Events:
