diff options
author | Yogita Urade <yogita.urade@windriver.com> | 2025-04-21 10:39:09 +0000 |
---|---|---|
committer | Armin Kuster <akuster808@gmail.com> | 2025-05-25 14:48:33 -0400 |
commit | 4c87bd7b937a0ab585352a3f3fb193d693106ed7 (patch) | |
tree | 3d89c52e10d5cd2895d9401857c245c1171b24fe /meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch | |
parent | 84fc57bacc8f609259c55f4ae4ab6ebd95a5ef4e (diff) | |
download | meta-openembedded-4c87bd7b937a0ab585352a3f3fb193d693106ed7.tar.gz |
poppler: fix CVE-2025-32365
Poppler before 25.04.0 allows crafted input files to trigger
out-of-bounds reads in the JBIG2Bitmap::combine function in
JBIG2Stream.cc because of a misplaced isOk check.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-32365
Upstream patch:
https://gitlab.freedesktop.org/poppler/poppler/-/commit/1f151565bbca5be7449ba8eea6833051cc1baa41
Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-twisted/CVE-2024-41671-0001.patch')
0 files changed, 0 insertions, 0 deletions