CVE-2025-32365
CVSS 3.1 Score 4 of 10 (medium)
Details
Published Apr 5, 2025
Updated: Apr 7, 2025
CWE ID 125
Summary
CVE-2025-32365 is a newly disclosed vulnerability affecting Poppler before version 25.04.0. This issue grants attackers the ability to trigger out-of-bounds reads in the JBIG2Bitmap::combine function within JBIG2Stream.cc. The root cause is a misplaced isOk check in the code, which allows crafted input files to exploit this weakness. Successful exploitation could potentially lead to significant data leakage or system instability. Users are encouraged to update Poppler to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.