In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for Centos:7
poppler-cpp-devel
.
Note: Versions mentioned in the description apply only to the upstream poppler-cpp-devel
package and not the poppler-cpp-devel
package as distributed by Centos
.
See How to fix?
for Centos:7
relevant fixed versions and status.
Poppler is a PDF rendering library. Versions prior to 25.06.0 use std::atomic_int
for reference counting. Because std::atomic_int
is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.