Echo: poppler: security update to 25.03.0-5+deb13u2+e1

high Tenable Cloud Security Plugin ID 457658

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free
(write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot
class. The issue arises from the use of raw pointers to elements of a `std::vector`, which can lead to
dangling pointers when the vector is resized. The vulnerability stems from the way that refToParentMap
stores references to `std::vector` elements using raw pointers. These pointers may become invalid when the
vector is resized. This vulnerability is a common security problem involving the use of raw pointers to
`std::vectors`. Internally, `std::vector `stores its elements in a dynamically allocated array. When the
array reaches its capacity and a new element is added, the vector reallocates a larger block of memory and
moves all the existing elements to the new location. At this point if any pointers to elements are stored
before a resize occurs, they become dangling pointers once the reallocation happens. Version 25.10.0
contains a patch for the issue. (CVE-2025-52885)

Solution

Update the poppler library and its related packages to version 25.03.0-5+deb13u2+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-52885

Plugin Details

Severity: High

ID: 457658

Version: Revision 1.2

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

Percentile: 96.82

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 6.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2025-52885

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/13/2026

Vulnerability Publication Date: 5/13/2026

Reference Information

CVE: CVE-2025-52885