CNNVD-202508-234 Information
CNNVD ID
CNNVD-202508-234
Related CVE
- CNNVD Published: 2025-08-04
Description (Chinese)
Freedesktop Poppler是Freedesktop社区的一个用于生成PDF的C++类库,该库是从Xpdf(PDF阅读器)继承而来。 Freedesktop Poppler v25.04.0版本存在安全漏洞,该漏洞源于程序退出时未清除包含PDF流对象的堆内存,可能导致敏感信息泄露。
Description (English)
Freedesktop Poppler is a C++ library for the production of PDF in the Freedesktop community, inherited from Xpdf (PDF reader). Freedesktop Poppler v25.04.0 has a security loophole, which results from the failure to clear the memory of a PDF streaming object at the time the program exits, which may lead to the disclosure of sensitive information.
Hazard Level
Critical
Vulnerability Type
其他
Affected Vendor
Freedesktop
Published
2025-08-04
Last Modified
2026-02-24
References
http://poppler.com https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081 https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621 https://github.com/Landw-hub/CVE-2025-50422 http://freedesktop.com https://nvd.nist.gov/vuln/detail/CVE-2025-50422 https://vigilance.fr/vulnerability/Cairo-assertion-error-via-cairo-ft-unscaled-font-fini-48263
Patch
https://poppler.freedesktop.org/
Share on: