Impact
This vulnerability originates in the Poppler fork maintained by Innodata Labs, where the JPX decoder’s readCodestream function uses values from the JPEG2000 SIZ segment to allocate memory without proper validation. An attacker can craft a PDF containing a JPXDecode image that forces the application to allocate an unbounded amount of memory, leading to an out‑of‑memory state and terminating the pdftoppm process. The result is a denial‑of‑service that can be triggered remotely without any local privilege.
Affected Systems
Affected software is the Poppler fork maintained by Innodata Labs. The standard Poppler distribution has removed the JPX decoder, so only deployments of this third‑party fork are impacted. No specific version range is listed, therefore all instances running the unpatched Innodata Labs build should be treated as vulnerable until a fix is released.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. No EPSS score is available, but the lack of a public fix and the remote nature of the trigger imply a non‑negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit this by sending a malicious PDF to any service that processes PDFs through the Innodata Labs Poppler fork; the flaw requires only the ability to provide a crafted file, making it a straightforward DoS attack vector.
OpenCVE Enrichment