Junglewise Threat Intelligence

CVE-2025-50420: freedesktop Poppler infinite recursion in pdfseparate

CVE-2025-50420 · Severity: medium · CVSS 6.5 · Published 2025-08-04

Technologies: Freedesktop.Org Poppler. Vendors: Freedesktop.Org.

Executive brief

A vulnerability in the pdfseparate utility, part of the Poppler PDF processing library, can allow an attacker to crash the application. By providing a specially crafted PDF file, an attacker can cause the software to enter an infinite loop, leading to a denial-of-service state. This affects systems that use Poppler to automate the extraction of pages from PDF documents.

Technical details

A vulnerability classified as uncontrolled recursion (CWE-674) exists in the pdfseparate utility of Poppler version 25.04.0. The flaw is triggered when the utility processes a maliciously crafted PDF file designed to induce infinite recursion during parsing or separation. This is a remote attack vector requiring user interaction, specifically the opening or processing of the malicious file. Successful exploitation results in a stack overflow or exhaustion of resources, causing the utility to crash (Denial of Service). While the advisory focuses on version 25.04.0, NVD data suggests versions up to (but excluding) 25.07.0 may be affected.

Affected products

  • freedesktop.org Poppler 25.04.0

Timeline

  • 2025-08-04: disclosed
  • 2025-08-04: advisory

References

Related threats