Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
ECHO-6943-4e40-cbe5
See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-6943-4e40-cbe5.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-6943-4e40-cbe5
Upstream
CVE-2017-2820
Withdrawn
2025-12-09T15:30:04Z
Published
2025-08-29T01:36:58Z
Modified
2026-09-15T00:47:34Z
Summary
Debian's poppler is built to use the external openjpeg library for JPEG 2000 image parsing, not Poppler's internal (vulnerable) JPEG 2000 decoder. Therefore this CVE does not apply to the Debian build.
Details
References
https://advisory.echohq.com/cve/CVE-2017-2820
Affected packages
Echo
/
poppler
Package
Name
poppler
Purl
pkg:deb/echo/poppler
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
25.03.0-5+deb13u2+e1
Database specific
source
"https://advisory.echohq.com/osv/ECHO-6943-4e40-cbe5.json"
ECHO-6943-4e40-cbe5 - OSV