Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor).
References
Configurations
No configuration.
History
03 Oct 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.9 |
02 Oct 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
01 Oct 2025, 20:18
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-674 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
01 Oct 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-01 19:15
Updated : 2025-10-03 17:15
NVD link : CVE-2025-43718
Mitre link : CVE-2025-43718
CVE.ORG link : CVE-2025-43718
JSON object : View
Products Affected
No product.
CWE
CWE-674
Uncontrolled Recursion