Описание
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
A flaw was found in Poppler. This vulnerability allows out-of-bounds reads via crafted input files that trigger the JBIG2Bitmap::combine function due to a misplaced isOk check.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | poppler | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-poppler022 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | poppler | Out of support scope | ||
| Red Hat Enterprise Linux 10 | poppler | Fixed | RHSA-2026:0128 | 06.01.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | poppler | Fixed | RHSA-2026:1090 | 26.01.2026 |
| Red Hat Enterprise Linux 8 | poppler | Fixed | RHSA-2026:0130 | 06.01.2026 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | poppler | Fixed | RHSA-2026:1091 | 26.01.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | poppler | Fixed | RHSA-2026:0774 | 19.01.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | poppler | Fixed | RHSA-2026:0774 | 19.01.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | poppler | Fixed | RHSA-2026:0773 | 19.01.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
Poppler before 25.04.0 allows crafted input files to trigger out-of-bo ...
EPSS
3.3 Low
CVSS3