GSA-6334-1: Poppler Security Update – Critical Fix Released
Gnoppix 23/25 and 25 users must apply an urgent security update for the poppler PDF rendering library. The update addresses a denial-of-service vulnerability triggered by malformed PDF files.
Attack Vector and Impact
The flaw allows an attacker to crash applications using poppler, such as document viewers or PDF processors. This is achieved by sending a specially crafted PDF file that triggers an infinite loop or excessive resource consumption.
Affected Systems
All current Gnoppix releases running poppler are affected. This includes both stable and testing branches.
Remediation Steps
- Upgrade immediately to the patched poppler package version.
- Restart all services or applications that rely on the library after installation.
- Verify the update with the standard package manager update command.
Technical Details
The vulnerability is a logic error in poppler’s internal file parsing routine. No upstream identifier has been assigned as of this announcement. The Gnoppix security team backported the fix from the upstream development branch. - Please update your systems.