UbuntuUpdates.org

Package "poppler"

Name: poppler

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • GObject introspection data for poppler-glib
  • PDF rendering library -- development files (CPP interface)
  • PDF rendering library (CPP shared library)
  • PDF rendering library -- development files

Latest version: 24.02.0-1ubuntu9.10
Release: noble (24.04)
Level: security
Repository: main

Links



Other versions of "poppler" in Noble

Repository Area Version
base universe 24.02.0-1ubuntu9
base main 24.02.0-1ubuntu9
security universe 24.02.0-1ubuntu9.10
updates main 24.02.0-1ubuntu9.10
updates universe 24.02.0-1ubuntu9.10

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 24.02.0-1ubuntu9.10 2026-10-07 15:38:18 UTC

poppler (24.02.0-1ubuntu9.10) noble-security; urgency=medium

  * SECURITY UPDATE: overflow in FoFiTrueType::cvtSfnts
    - debian/patches/CVE-2026-102620.patch: Fix integer overflow in
      FoFiTrueType::cvtSfnts in fofi/FoFiTrueType.cc.
    - CVE-2026-102620
  * SECURITY UPDATE: overflow in SplashClip::clipToPath
    - debian/patches/CVE-2026-102621.patch: Fix integer overflow in
      SplashClip::clipToPath in splash/SplashClip.cc.
    - CVE-2026-102621
  * SECURITY UPDATE: null pointer deref issue
    - debian/patches/CVE-2026-93312.patch: Fix nullptr + number in
      poppler/JBIG2Stream.cc.
    - CVE-2026-93312
  * SECURITY UPDATE: overflow in JBIG2Stream::readCodeTableSeg
    - debian/patches/CVE-2026-93313.patch: Fix integer overflow in
      JBIG2Stream::readCodeTableSeg in poppler/JBIG2Stream.cc.
    - CVE-2026-93313
  * SECURITY UPDATE: overflow in FoFiTrueType::mapCodeToGID
    - debian/patches/CVE-2026-93314.patch: FoFiTrueType::mapCodeToGID: Improve
      b*12 overflow check in fofi/FoFiTrueType.cc.
    - CVE-2026-93314

 -- Marc Deslauriers Tue, 06 Oct 2026 13:36:43 -0400

Source diff to previous version
CVE-2026-102620 A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFi
CVE-2026-102621 A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc
CVE-2026-93312 A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulat
CVE-2026-93313 A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG
CVE-2026-93314 A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc.

Version: 24.02.0-1ubuntu9.9 2026-06-08 14:08:07 UTC

  poppler (24.02.0-1ubuntu9.9) noble-security; urgency=medium

  * SECURITY UPDATE: integer overflow in Splash backend
    - debian/patches/CVE-2026-10118.patch: SplashOutputDev: Fix integer overflow
      in tilingPatternFill in poppler/SplashOutputDev.cc.
    - CVE-2026-10118

 -- Marc Deslauriers <email address hidden> Thu, 04 Jun 2026 10:46:44 -0400

Source diff to previous version
CVE-2026-10118 A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered

Version: 24.02.0-1ubuntu9.8 2025-11-05 14:07:05 UTC

  poppler (24.02.0-1ubuntu9.8) noble-security; urgency=medium

  * SECURITY UPDATE: User after free
    - debian/patches/CVE-2025-52885.patch: check for duplicate
      entries in poppler/StructTreeRoot.cc.
    - CVE-2025-52885

 -- Leonidas Da Silva Barbosa <email address hidden> Mon, 03 Nov 2025 07:57:48 -0300

Source diff to previous version
CVE-2025-52885 Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in

Version: 24.02.0-1ubuntu9.7 2025-10-06 14:07:27 UTC

  poppler (24.02.0-1ubuntu9.7) noble-security; urgency=medium

  * SECURITY UPDATE: stack consumption via metadata
    - debian/patches/CVE-2025-43718.patch: make sure regex doesn't stack
      overflow by limiting it in poppler/PDFDoc.cc.
    - CVE-2025-43718

 -- Marc Deslauriers <email address hidden> Fri, 03 Oct 2025 07:36:12 -0400

Source diff to previous version
CVE-2025-43718 Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFE

Version: 24.02.0-1ubuntu9.6 2025-08-20 20:56:27 UTC

  poppler (24.02.0-1ubuntu9.6) noble-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2025-50420.patch: don't continue
      recursing in PDFDoc in poppler/PDFDoc.cc.
    - CVE-2025-50420

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 12 Aug 2025 12:43:49 -0300

CVE-2025-50420 An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file.



About   -   Send Feedback to @ubuntu_updates