Skip to content

Conversation

jlsec-bot
Copy link
Contributor

This action searched freedesktop:poppler, checking 88 (+1) advisories from NVD and 4 (+3) from EUVD for advisories that pertain here. It identified 11 advisories as being related to the Julia package(s): Poppler_jll.

6 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2024-56378 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at <= 24.12.0 includes all versions
  • CVE-2025-32364 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.04.0 includes all versions
  • CVE-2025-32365 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.04.0 includes all versions
  • CVE-2025-43903 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.04.0 includes all versions
  • CVE-2025-50420 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.07.0 includes all versions
  • CVE-2025-52886 for packages: Poppler_jll
    • Poppler_jll computed ["*"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
      • freedesktop:poppler at < 25.06.0 includes all versions

5 advisories found concrete vulnerable ranges

  • CVE-2021-30860 for packages: Poppler_jll
    • Poppler_jll computed ["< 23.12.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
  • CVE-2022-38171 for packages: Poppler_jll
    • Poppler_jll computed ["< 23.12.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
  • CVE-2022-38784 for packages: Poppler_jll
    • Poppler_jll computed ["< 23.12.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
  • CVE-2023-34872 for packages: Poppler_jll
    • Poppler_jll computed ["< 23.12.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}
  • CVE-2024-6239 for packages: Poppler_jll
    • Poppler_jll computed ["< 24.6.0+0"]. Its latest version (24.6.0+0) has components: {poppler = "24.06.0", poppler-ink = "24.06.0"}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants