Impact
A flaw in Poppler’s SampledFunction::SampledFunction routine in poppler/Function.cc lets an attacker manipulate the BitsPerSample argument to cause an integer overflow. The overflow is triggered by a crafted PDF, and the exploit is publicly available, indicating that remote exploitation is possible.*The vulnerability is a classic integer overflow (CWE-189/190).*
Affected Systems
The vulnerability affects Freedesktop Poppler version 26.07.0. No other affected product versions are listed in the data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. The attack vector is remote and the exploit is publicly available, meaning that a system using Poppler 26.07.0 to process a malicious PDF that contains a crafted SampledFunction could be exposed if the vulnerability is exercised.
OpenCVE Enrichment