Floating-Point Exception in Poppler Affects Applications Handling Malformed Inputs
CVE-2025-32364

4MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 April 2025

What is CVE-2025-32364?

A vulnerability exists in the PSStack::roll function of Poppler, where a floating-point exception can occur when the application processes malformed inputs related to INT_MIN. This flaw can lead to application crashes, impacting system stability and potentially exposing users to further risk. To mitigate this issue, it is advisable to update to Poppler version 25.04.0 or later, which addresses these vulnerabilities.

Affected Version(s)

Poppler 0 < 25.04.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32364 : Floating-Point Exception in Poppler Affects Applications Handling Malformed Inputs