yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-34872
Component Overview
Vulnerability Overview
Name
CVE-2023-34872
Source
NVD (
link
)
Debian (
link
)
Description
A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
CWEs
CWE-400
Published Date
Jul 31, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe
Patch
https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399
Exploit
https://gitlab.freedesktop.org/poppler/poppler/-/commit/591235c8b6c65a2eee88991b9ae73490fd9afdfe
Patch
https://gitlab.freedesktop.org/poppler/poppler/-/issues/1399
Exploit
Analysis
#
Affected Component
Analysis
poppler
Patched
Vulnerability Ratings
#
5.5
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
poppler
buildroot
2025.02.x
25.10.0
Not Affected
poppler
buildroot
master
25.10.0
Not Affected
poppler
yocto
master
25.12.0
Not Affected
poppler
yocto
scarthgap
23.04.0
Patched
Resolved with patches
#
poppler (yocto:kirkstone)
#
Title
Author
Resolve
1
OutlineItem::open: Fix crash on malformed files
Albert Astals Cid <aacid@kde.org>
CVE-2023-34872
poppler (yocto:scarthgap)
#
Title
Author
Resolve
1
OutlineItem::open: Fix crash on malformed files
Albert Astals Cid <aacid@kde.org>
CVE-2023-34872