libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "317993174120115032034425532424644821710", "305378439465977260469268437524020531985", "32640778084084373713215398513815775002", "70173714017035807853509237497907509723", "43426555449729616035109266427270452728", "86683275675615738987873687730256900326", "216949047248132767314281390003326586063", "154205541927650703791505449868426040208", "214084527060856846290639835030516078283", "279690928921326099697943468696789685032", "13772684557713579605756961918131262229", "277211677198523666325954819965416802661", "221527345707546910455034719714713038381", "14364649710699683163510119277671541926", "155372360500009015349401343898624495844", "15957322412323199208936407781506127751", "124922917649399959903537357783409463657", "20513912555904710286837369651662901604", "63795670196445050522573127708076372628", "189985544474809842633811341228835061913", "71252973307666370295246751685920290176", "109838867061695065897441260424740739784", "246269872951396569713295466612724197694", "68462969337530924193766396260853523921", "284352439716032173352938472374950851630" ] }, "signature_type": "Line", "source": "https://gitlab.freedesktop.org/poppler/poppler@ade9b5ebed44b0c15522c27669ef6cdf93eff84e", "signature_version": "v1", "target": { "file": "poppler/JBIG2Stream.cc" }, "deprecated": false, "id": "CVE-2024-56378-9e8286cc" }, { "digest": { "function_hash": "138063338476241068198743373692070869340", "length": 3079.0 }, "signature_type": "Function", "source": "https://gitlab.freedesktop.org/poppler/poppler@ade9b5ebed44b0c15522c27669ef6cdf93eff84e", "signature_version": "v1", "target": { "file": "poppler/JBIG2Stream.cc", "function": "JBIG2Bitmap::combine" }, "deprecated": false, "id": "CVE-2024-56378-a9dc4513" } ] }