USN-7675-1: poppler vulnerability
USN-7675-1: poppler vulnerability
Publication date: 28 July 2025
Overview: poppler could be made to crash or run programs if it opened a specially crafted file.
Packages
poppler - PDF rendering library
Details
Kevin Backhouse discovered that poppler incorrectly handled documents with
a large number of annotations. If a user or automated system were tricked
into opening a specially crafted document, a remote attacker could use
this issue to cause poppler to consume resources, leading to a denial of
service, or possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
24.04 noble
- libpoppler134 – 24.02.0-1ubuntu9.5
- poppler-utils – 24.02.0-1ubuntu9.5
-