CVE-2025-32365

CVSS 3.1 Score 4 of 10 (medium)

Details

Published Apr 5, 2025
Updated: Apr 7, 2025
CWE ID 125

Summary

CVE-2025-32365 is a newly disclosed vulnerability affecting Poppler before version 25.04.0. This issue grants attackers the ability to trigger out-of-bounds reads in the JBIG2Bitmap::combine function within JBIG2Stream.cc. The root cause is a misplaced isOk check in the code, which allows crafted input files to exploit this weakness. Successful exploitation could potentially lead to significant data leakage or system instability. Users are encouraged to update Poppler to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share