CVE-2025-43718

Name
CVE-2025-43718
Description
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor).
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/ShadowByte1/CVE-Reports/blob/main/CVE-2025-43718.md
cve@mitre.org https://gitlab.freedesktop.org/poppler/poppler/-/commit/f54b815672117c250420787c8c006de98e8c7408

Match rules

CPE URI Source package Min version Max version
poppler >= 24.06.1 < 25.04.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
poppler edge-main 25.01.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
poppler edge-main 25.02.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable