{"id":"ECHO-9bf0-cd5c-d541","summary":"The vulnerable code is only compiled when building with -DENABLE_DCTDECODER=unmaintained, which Debian does not use.\n\nThis CVE was originally filed against xpdf. While poppler shares some code history\nwith xpdf, the vulnerable path is not active in Debian's builds.\nhttps://security-tracker.debian.org/tracker/CVE-2022-24106\n","modified":"2026-09-15T03:33:36.349085606Z","published":"2025-09-15T01:09:57.869296Z","withdrawn":"2025-12-09T15:30:04.042Z","upstream":["CVE-2022-24106"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2022-24106"}],"affected":[{"package":{"name":"poppler","ecosystem":"Echo","purl":"pkg:deb/echo/poppler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.03.0-5+deb13u2+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-9bf0-cd5c-d541.json"}}],"schema_version":"1.9.0"}