ECHO-9bf0-cd5c-d541

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-9bf0-cd5c-d541.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-9bf0-cd5c-d541
Upstream
Withdrawn
2025-12-09T15:30:04Z
Published
2025-09-15T01:09:57Z
Modified
2026-09-15T03:33:36Z
Summary
The vulnerable code is only compiled when building with -DENABLE_DCTDECODER=unmaintained, which Debian does not use. This CVE was originally filed against xpdf. While poppler shares some code history with xpdf, the vulnerable path is not active in Debian's builds. https://security-tracker.debian.org/tracker/CVE-2022-24106
Details
References

Affected packages

Echo / poppler

Package

Name
poppler
Purl
pkg:deb/echo/poppler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.03.0-5+deb13u2+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-9bf0-cd5c-d541.json"