ECHO-6943-4e40-cbe5

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-6943-4e40-cbe5.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-6943-4e40-cbe5
Upstream
Withdrawn
2025-12-09T15:30:04Z
Published
2025-08-29T01:36:58Z
Modified
2026-09-15T00:47:34Z
Summary
Debian's poppler is built to use the external openjpeg library for JPEG 2000 image parsing, not Poppler's internal (vulnerable) JPEG 2000 decoder. Therefore this CVE does not apply to the Debian build.
Details
References

Affected packages

Echo / poppler

Package

Name
poppler
Purl
pkg:deb/echo/poppler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.03.0-5+deb13u2+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-6943-4e40-cbe5.json"