ECHO-ff9b-787b-df82

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-ff9b-787b-df82.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-ff9b-787b-df82
Upstream
Withdrawn
2025-12-09T15:30:04Z
Published
2025-08-29T01:36:58Z
Modified
2026-09-15T00:47:34Z
Summary
The vulnerable code is in the internal JPX decoder (JPXStream::readUByte), but Debian builds poppler to use openjpeg instead. The vulnerable code exists in the source but is not used at runtime. https://security-tracker.debian.org/tracker/CVE-2017-9083
Details
References

Affected packages

Echo / poppler

Package

Name
poppler
Purl
pkg:deb/echo/poppler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
25.03.0-5+deb13u2+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-ff9b-787b-df82.json"