{"id":"ECHO-6943-4e40-cbe5","summary":"Debian's poppler is built to use the external openjpeg library for JPEG 2000 image parsing,\nnot Poppler's internal (vulnerable) JPEG 2000 decoder. Therefore this CVE does not apply\nto the Debian build.\n","modified":"2026-09-15T00:47:34.118342556Z","published":"2025-08-29T01:36:58.180653Z","withdrawn":"2025-12-09T15:30:04.042Z","upstream":["CVE-2017-2820"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2017-2820"}],"affected":[{"package":{"name":"poppler","ecosystem":"Echo","purl":"pkg:deb/echo/poppler"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.03.0-5+deb13u2+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-6943-4e40-cbe5.json"}}],"schema_version":"1.9.0"}