libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.
[
{
"source": "https://gitlab.freedesktop.org/poppler/poppler@ade9b5ebed44b0c15522c27669ef6cdf93eff84e",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"317993174120115032034425532424644821710",
"305378439465977260469268437524020531985",
"32640778084084373713215398513815775002",
"70173714017035807853509237497907509723",
"43426555449729616035109266427270452728",
"86683275675615738987873687730256900326",
"216949047248132767314281390003326586063",
"154205541927650703791505449868426040208",
"214084527060856846290639835030516078283",
"279690928921326099697943468696789685032",
"13772684557713579605756961918131262229",
"277211677198523666325954819965416802661",
"221527345707546910455034719714713038381",
"14364649710699683163510119277671541926",
"155372360500009015349401343898624495844",
"15957322412323199208936407781506127751",
"124922917649399959903537357783409463657",
"20513912555904710286837369651662901604",
"63795670196445050522573127708076372628",
"189985544474809842633811341228835061913",
"71252973307666370295246751685920290176",
"109838867061695065897441260424740739784",
"246269872951396569713295466612724197694",
"68462969337530924193766396260853523921",
"284352439716032173352938472374950851630"
]
},
"deprecated": false,
"id": "CVE-2024-56378-9e8286cc",
"target": {
"file": "poppler/JBIG2Stream.cc"
},
"signature_version": "v1"
},
{
"source": "https://gitlab.freedesktop.org/poppler/poppler@ade9b5ebed44b0c15522c27669ef6cdf93eff84e",
"signature_type": "Function",
"digest": {
"length": 3079.0,
"function_hash": "138063338476241068198743373692070869340"
},
"deprecated": false,
"id": "CVE-2024-56378-a9dc4513",
"target": {
"function": "JBIG2Bitmap::combine",
"file": "poppler/JBIG2Stream.cc"
},
"signature_version": "v1"
}
]