cvemon logocvemon logo

Activity

Trending

CVE-2025-32365

Published Apr 5, 2025

Last updated 3 months ago

CVSS medium 4.0
  1. Overview

  2. Scores

  3. Weaknesses

  4. Social media

  5. References

Overview

Description
Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
4
Impact score
1.4
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity
MEDIUM

Weaknesses

cve@mitre.org
CWE-125

Social media

Hype score
Not currently trending
  1. CVE-2025-32365 04/05/2025 10:15:19 PM BaseSeverity: MEDIUM Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in https://t.co/iDSfaIGqmh because of a misplace... https://t.co/Gpe1c9qxIA

    @CVETracker

    6 Apr 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. New post from https://t.co/uXvPWJy6tj (CVE-2025-32365 | Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0 File https://t.co/TtHKdSXwMl JBIG2Bitmap::combine out-of-bounds (Issue 1577)) has been published on https://t.co/t5mMC1XSp8

    @WolfgangSesin

    6 Apr 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-32365
  • https://gitlab.freedesktop.org/poppler/poppler/-/issues/1577
  • https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/1792
TRY INTRUDER
Intruder logo

© 2025 Intruder Systems Ltd.

AboutPrivacySitemapFeeds