{"id":"CVE-2022-37051","details":"An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.","modified":"2026-08-12T13:00:30.362584Z","published":"2023-08-22T00:00:00Z","related":["SUSE-SU-2023:3947-1","SUSE-SU-2023:3982-1","SUSE-SU-2023:3983-1","SUSE-SU-2023:3998-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37051.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00037.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37051.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37051"},{"type":"REPORT","url":"https://gitlab.freedesktop.org/poppler/poppler/-/issues/1276"},{"type":"FIX","url":"https://gitlab.freedesktop.org/poppler/poppler/-/commit/4631115647c1e4f0482ffe0491c2f38d2231337b"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/poppler/poppler","events":[{"introduced":"bb1651334abc11495fa0326c8d562243d2a4b055"},{"fixed":"4631115647c1e4f0482ffe0491c2f38d2231337b"}],"database_specific":{"cpe":"cpe:2.3:a:freedesktop:poppler:22.07.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"22.07.0"},{"last_affected":"22.07.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["22.07.0","poppler-22.07.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T13:00:30Z","vanir_signatures":[{"target":{"file":"utils/pdfunite.cc","function":"main"},"deprecated":false,"digest":{"function_hash":"28764470486843602958939409407758997154","length":9173},"id":"CVE-2022-37051-63729fdb","signature_type":"Function","signature_version":"v1","source":"https://gitlab.freedesktop.org/poppler/poppler@4631115647c1e4f0482ffe0491c2f38d2231337b"},{"digest":{"threshold":0.9,"line_hashes":["170290882310296810456314929611303034643","78553070465358417443683385211519538971","186036928005084795469260628047356388150","304268556259101396486102552340104773235","200357466328446893937247236235745470310","141811060519803977583428152046897105607","147467722345611451628054370197341527543","98829761298320392181832376116194825342"]},"id":"CVE-2022-37051-b3a952dc","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/poppler/poppler@4631115647c1e4f0482ffe0491c2f38d2231337b","target":{"file":"utils/pdfunite.cc"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37051.json"}}],"schema_version":"1.9.0"}