Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 05 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical pdfunite |
|
| CPEs | cpe:2.3:a:canonical:pdfunite:0.41.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Canonical
Canonical pdfunite |
Thu, 30 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Poppler-utils
Poppler-utils pdfunite |
|
| Vendors & Products |
Poppler-utils
Poppler-utils pdfunite |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmentation fault in the XRef::getEntry function within libpoppler by providing a specially crafted PDF file to the pdfunite utility. | |
| Title | PDFunite 0.41.0 Buffer Overflow via Malformed PDF | |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-30T15:22:38.658Z
Reserved: 2026-04-29T12:10:08.610Z
Link: CVE-2018-25306
Updated: 2026-04-30T13:11:20.086Z
Status : Analyzed
Published: 2026-04-29T20:16:26.043
Modified: 2026-05-05T14:22:22.727
Link: CVE-2018-25306
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:20:45Z