[ubuntu/questing-proposed] poppler 25.03.0-4ubuntu1 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Jul 25 17:00:20 UTC 2025


poppler (25.03.0-4ubuntu1) questing; urgency=medium

  * SECURITY UPDATE: DoS via reference count overflow
    - debian/patches/CVE-2025-52886.patch: limit amount of annots per
      document/page in poppler/Annot.cc, poppler/Page.cc.
    - CVE-2025-52886

Date: Fri, 25 Jul 2025 09:59:33 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/poppler/25.03.0-4ubuntu1
-------------- next part --------------
Format: 1.8
Date: Fri, 25 Jul 2025 09:59:33 -0400
Source: poppler
Built-For-Profiles: noudeb
Architecture: source
Version: 25.03.0-4ubuntu1
Distribution: questing
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 poppler (25.03.0-4ubuntu1) questing; urgency=medium
 .
   * SECURITY UPDATE: DoS via reference count overflow
     - debian/patches/CVE-2025-52886.patch: limit amount of annots per
       document/page in poppler/Annot.cc, poppler/Page.cc.
     - CVE-2025-52886
Checksums-Sha1:
 ca978179c7a4a51a78f52abca62c77d1b1342dec 4041 poppler_25.03.0-4ubuntu1.dsc
 c62d937ef1ec693c2b47219fd2ae4f5479214152 42204 poppler_25.03.0-4ubuntu1.debian.tar.xz
 4d594f456cd86504f38432ae58d994c6ca1e6544 20777 poppler_25.03.0-4ubuntu1_source.buildinfo
Checksums-Sha256:
 9314bdb0de8b031ec53d35d2b53d5b8b0b79fe888d1c2115cafc5f5b061e0910 4041 poppler_25.03.0-4ubuntu1.dsc
 46570a47365da52a538e9f00cb0d198956b54da15669c9a1eb1aa6320b42eabd 42204 poppler_25.03.0-4ubuntu1.debian.tar.xz
 ea40975982e1cff4832745183f67258022788a3c827ed70b6c44b53ea7895463 20777 poppler_25.03.0-4ubuntu1_source.buildinfo
Files:
 c44c18205841332e29eeb5b77dc3f168 4041 devel optional poppler_25.03.0-4ubuntu1.dsc
 9da7bd72dc254ac70e783ed20999c856 42204 devel optional poppler_25.03.0-4ubuntu1.debian.tar.xz
 413b6dba3132f268570ee7c0efb5486e 20777 devel optional poppler_25.03.0-4ubuntu1_source.buildinfo
Original-Maintainer: Debian freedesktop.org maintainers <pkg-freedesktop-maintainers at lists.alioth.debian.org>


More information about the Questing-changes mailing list